GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
86 advisories
Filter by severity
Kea configuration and API directives can be used to overwrite arbitrary files, subject to...
Moderate
Unreviewed
CVE-2025-32802
was published
May 28, 2025
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File...
Moderate
Unreviewed
CVE-2025-4602
was published
May 24, 2025
External control of file name or path in Microsoft Defender for Endpoint allows an authorized...
Moderate
Unreviewed
CVE-2025-26684
was published
May 13, 2025
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a...
Moderate
Unreviewed
CVE-2025-1056
was published
Apr 23, 2025
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables...
Moderate
Unreviewed
CVE-2025-0124
was published
Apr 11, 2025
External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized...
Moderate
Unreviewed
CVE-2025-29819
was published
Apr 8, 2025
A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x....
Moderate
Unreviewed
CVE-2025-2982
was published
Mar 31, 2025
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform...
Moderate
Unreviewed
CVE-2025-24996
was published
Mar 11, 2025
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform...
Moderate
Unreviewed
CVE-2025-24054
was published
Mar 11, 2025
The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all...
Moderate
Unreviewed
CVE-2025-1730
was published
Mar 1, 2025
The account file upload functionality in Syspass 3.2.x fails to properly handle special...
Moderate
Unreviewed
CVE-2025-25478
was published
Mar 1, 2025
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web...
Moderate
Unreviewed
CVE-2025-0109
was published
Feb 12, 2025
NTLM Hash Disclosure Spoofing Vulnerability
Moderate
Unreviewed
CVE-2025-21377
was published
Feb 11, 2025
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti...
Moderate
Unreviewed
CVE-2024-12058
was published
Feb 11, 2025
Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local...
Moderate
Unreviewed
CVE-2025-0630
was published
Feb 4, 2025
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-12267
was published
Jan 31, 2025
The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File...
Moderate
Unreviewed
CVE-2024-12861
was published
Jan 30, 2025
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an...
Moderate
Unreviewed
CVE-2025-0105
was published
Jan 11, 2025
A vulnerability was found in Campcodes School Faculty Scheduling System 1.0 and classified as...
Moderate
Unreviewed
CVE-2025-0211
was published
Jan 4, 2025
A vulnerability was found in TCS BaNCS 10. It has been classified as problematic. This affects an...
Moderate
Unreviewed
CVE-2025-0202
was published
Jan 4, 2025
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress...
Moderate
Unreviewed
CVE-2024-12875
was published
Dec 21, 2024
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and...
Moderate
Unreviewed
CVE-2024-12357
was published
Dec 9, 2024
Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
Moderate
CVE-2024-10492
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
NTLM Hash Disclosure Spoofing Vulnerability
Moderate
Unreviewed
CVE-2024-43451
was published
Nov 12, 2024
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all...
Moderate
Unreviewed
CVE-2023-5816
was published
Oct 30, 2024
ProTip!
Advisories are also available from the
GraphQL API