GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
6,383 advisories
Filter by severity
An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal...
High
Unreviewed
CVE-2024-50626
was published
Dec 10, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-53790
was published
Dec 9, 2024
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-11010
was published
Dec 7, 2024
The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all...
High
Unreviewed
CVE-2024-10516
was published
Dec 6, 2024
The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents...
High
Unreviewed
CVE-2024-11585
was published
Dec 6, 2024
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir...
Moderate
Unreviewed
CVE-2024-10933
was published
Dec 5, 2024
JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in...
High
Unreviewed
CVE-2024-53523
was published
Dec 5, 2024
Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.
High
Unreviewed
CVE-2024-53490
was published
Dec 5, 2024
Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability
Moderate
CVE-2024-54132
was published
for
github.com/cli/cli
(Go)
Dec 4, 2024
The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local...
High
Unreviewed
CVE-2024-11952
was published
Dec 4, 2024
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-11398
was published
Dec 4, 2024
An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0...
Moderate
Unreviewed
CVE-2024-53566
was published
Dec 2, 2024
Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could...
Critical
Unreviewed
CVE-2024-11992
was published
Nov 29, 2024
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API....
High
Unreviewed
CVE-2024-11481
was published
Nov 29, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-52481
was published
Nov 28, 2024
The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File...
High
Unreviewed
CVE-2024-9669
was published
Nov 28, 2024
The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers...
Low
Unreviewed
CVE-2024-46939
was published
Nov 28, 2024
Jenkins Filesystem List Parameter Plugin has Path Traversal vulnerability
Moderate
CVE-2024-54004
was published
for
aendter.jenkins.plugins:filesystem-list-parameter-plugin
(Maven)
Nov 27, 2024
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware...
High
Unreviewed
CVE-2024-11667
was published
Nov 27, 2024
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress...
Moderate
Unreviewed
CVE-2024-11219
was published
Nov 27, 2024
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may...
Critical
Unreviewed
CVE-2024-53676
was published
Nov 27, 2024
Improper processing of some parameters of installed_emanual_list.html leads to a path traversal...
High
Unreviewed
CVE-2024-33605
was published
Nov 26, 2024
libre-chat Path Traversal vulnerability
Moderate
CVE-2024-52787
was published
for
libre-chat
(pip)
Nov 25, 2024
A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by...
High
Unreviewed
CVE-2024-11664
was published
Nov 25, 2024
The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions...
High
Unreviewed
CVE-2024-10803
was published
Nov 23, 2024
ProTip!
Advisories are also available from the
GraphQL API