GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,731
Erlang
35
GitHub Actions
29
Go
2,308
Maven
5,000+
npm
3,949
NuGet
711
pip
3,727
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
12 advisories
Filter by severity
Path Traversal in scout-browser
Moderate
CVE-2022-1554
was published
for
scout-browser
(pip)
May 4, 2022
Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs
Moderate
CVE-2023-1176
was published
for
mlflow
(pip)
Mar 24, 2023
MLflow Path Traversal vulnerability
Critical
CVE-2023-3765
was published
for
mlflow
(pip)
Jul 19, 2023
Ansible symlink attack vulnerability
Moderate
CVE-2023-5115
was published
for
ansible
(pip)
Dec 28, 2023
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery when opening XLSX file
High
CVE-2024-45290
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled
Moderate
CVE-2024-45291
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
Critical
CVE-2024-47883
was published
for
org.openrefine.dependencies:butterfly
(Maven)
Oct 24, 2024
Deep Java Library path traversal issue
Critical
CVE-2025-0851
was published
for
ai.djl:api
(Maven)
Jan 29, 2025
DB-GPT Absolute Path Traversal vulnerability
Critical
CVE-2024-10831
was published
for
dbgpt
(pip)
Mar 20, 2025
H2O Vulnerable to Arbitrary File Overwrite via File Export
High
CVE-2024-6854
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
AgentScope arbitrary file download vulnerability in rpc_agent_client
High
CVE-2024-8501
was published
for
agentscope
(pip)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API