GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,480
Maven
5,000+
npm
4,097
NuGet
734
pip
3,910
Pub
12
RubyGems
945
Rust
1,014
Swift
39
Unreviewed advisories
All unreviewed
5,000+
226 advisories
Filter by severity
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic....
Moderate
Unreviewed
CVE-2024-12482
was published
Dec 12, 2024
Microsoft SharePoint Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-49062
was published
Dec 12, 2024
Ansible galaxy-importer Path Traversal vulnerability
Moderate
CVE-2023-5189
was published
for
galaxy-importer
(pip)
Nov 15, 2023
The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote...
High
Unreviewed
CVE-2024-11067
was published
Nov 11, 2024
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of...
Critical
Unreviewed
CVE-2024-11311
was published
Nov 18, 2024
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of...
Critical
Unreviewed
CVE-2024-11313
was published
Nov 18, 2024
The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers...
High
Unreviewed
CVE-2024-11310
was published
Nov 18, 2024
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of...
Critical
Unreviewed
CVE-2024-11315
was published
Nov 18, 2024
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of...
Critical
Unreviewed
CVE-2024-11312
was published
Nov 18, 2024
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of...
Critical
Unreviewed
CVE-2024-11314
was published
Nov 18, 2024
The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers...
High
Unreviewed
CVE-2024-11309
was published
Nov 18, 2024
registry-support: decompress can delete files outside scope via relative paths
Moderate
CVE-2024-1485
was published
for
github.com/devfile/registry-support/registry-library
(Go)
Feb 14, 2024
GuardDog vulnerable to arbitrary file write when scanning a specially-crafted PyPI package
Low
CVE-2022-23531
was published
for
guarddog
(pip)
Dec 2, 2022
Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing...
High
Unreviewed
CVE-2024-10200
was published
Oct 21, 2024
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user...
High
Unreviewed
CVE-2024-45731
was published
Oct 14, 2024
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter,...
High
Unreviewed
CVE-2024-9983
was published
Oct 15, 2024
Maliciously Crafted Model Archive Can Lead To Arbitrary File Write
High
CVE-2021-41127
was published
for
rasa
(pip)
Oct 22, 2021
Relative Path Traversal vulnerability in James Park Analyse Uploads allows Relative Path...
High
Unreviewed
CVE-2024-49253
was published
Oct 16, 2024
: Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Path...
High
Unreviewed
CVE-2024-47637
was published
Oct 16, 2024
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing...
Moderate
Unreviewed
CVE-2024-9923
was published
Oct 14, 2024
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing...
High
Unreviewed
CVE-2024-9922
was published
Oct 14, 2024
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was...
Moderate
Unreviewed
CVE-2024-47948
was published
Oct 8, 2024
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary...
Moderate
Unreviewed
CVE-2024-47949
was published
Oct 8, 2024
Lord of Large Language Models (LoLLMs) path traversal vulnerability in the api open_personality_folder endpoint
Moderate
CVE-2024-6985
was published
for
lollms
(pip)
Oct 11, 2024
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated,...
High
Unreviewed
CVE-2024-20449
was published
Oct 2, 2024
ProTip!
Advisories are also available from the
GraphQL API