GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,192 advisories
Filter by severity
Mattermost Path Traversal vulnerability
High
CVE-2025-9079
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 19, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33036
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33037
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33033
was published
Aug 29, 2025
Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via...
Critical
Unreviewed
CVE-2012-10054
was published
Aug 13, 2025
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0....
Moderate
Unreviewed
CVE-2025-10709
was published
Sep 19, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-10468
was published
Sep 19, 2025
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization...
Moderate
Unreviewed
CVE-2025-10708
was published
Sep 19, 2025
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
Low
CVE-2025-59414
was published
for
nuxt
(npm)
Sep 17, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine
Moderate
CVE-2025-59352
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker...
High
Unreviewed
CVE-2025-33035
was published
Jun 6, 2025
In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is...
Moderate
Unreviewed
CVE-2025-34173
was published
Sep 9, 2025
A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote...
Critical
Unreviewed
CVE-2025-59304
was published
Sep 17, 2025
CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral'...
Moderate
Unreviewed
CVE-2025-35430
was published
Sep 17, 2025
In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not...
Moderate
Unreviewed
CVE-2025-34176
was published
Sep 9, 2025
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates,...
Moderate
Unreviewed
CVE-2025-9215
was published
Sep 17, 2025
The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File...
Moderate
Unreviewed
CVE-2025-10050
was published
Sep 17, 2025
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure...
High
Unreviewed
CVE-2025-34185
was published
Sep 16, 2025
Langchain-Chatchat has a Path Traversal vulnerability
Low
CVE-2025-6853
was published
for
langchain-chatchat
(pip)
Jun 29, 2025
A parsing issue in the handling of directory paths was addressed with improved path validation....
Moderate
Unreviewed
CVE-2025-43314
was published
Sep 16, 2025
A parsing issue in the handling of directory paths was addressed with improved path validation....
Moderate
Unreviewed
CVE-2025-43190
was published
Sep 16, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2024-47265
was published
Feb 13, 2025
wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api...
Moderate
Unreviewed
CVE-2025-49089
was published
Sep 15, 2025
A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element...
Moderate
Unreviewed
CVE-2025-10472
was published
Sep 15, 2025
Flowise has arbitrary file access due to missing chat flow id validation
Critical
GHSA-q67q-549q-p849
was published
for
flowise
(npm)
Sep 15, 2025
ProTip!
Advisories are also available from the
GraphQL API