GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,205
Erlang
31
GitHub Actions
19
Go
1,986
Maven
5,000+
npm
3,703
NuGet
661
pip
3,329
Pub
11
RubyGems
884
Rust
844
Swift
36
Unreviewed advisories
All unreviewed
5,000+
358 advisories
Filter by severity
PrestaShop file access through path traversal
Moderate
CVE-2023-39528
was published
for
prestashop/prestashop
(Composer)
Aug 9, 2023
PrestaShop path traversal
Moderate
CVE-2023-39525
was published
for
prestashop/prestashop
(Composer)
Aug 9, 2023
Cloudflare Wrangler directory traversal vulnerability
Moderate
CVE-2023-3348
was published
for
wrangler
(npm)
Aug 3, 2023
Pimcore Path Traversal Vulnerability in AssetController:importServerFilesAction
Moderate
CVE-2023-38708
was published
for
pimcore/pimcore
(Composer)
Aug 3, 2023
@simonsmith/cypress-image-snapshothas fix for insecure snapshot file names
Moderate
CVE-2023-38695
was published
for
@simonsmith/cypress-image-snapshot
(npm)
Aug 1, 2023
OpenRefine vulnerable to zip slip in project import
Moderate
CVE-2023-37476
was published
for
org.openrefine:main
(Maven)
Jul 18, 2023
Jenkins MathWorks Polyspace Plugin vulnerable to arbitrary file read
Moderate
CVE-2023-37960
was published
for
com.mathworks.polyspace.jenkins:mathworks-polyspace
(Maven)
Jul 12, 2023
Apache Airflow Path Traversal vulnerability
Moderate
CVE-2023-22887
was published
for
apache-airflow
(pip)
Jul 12, 2023
Apache MINA SSHD information disclosure vulnerability
Moderate
CVE-2023-35887
was published
for
org.apache.sshd:sshd-common
(Maven)
Jul 10, 2023
Gatsby develop server has Local File Inclusion vulnerability
Moderate
CVE-2023-34238
was published
for
gatsby
(npm)
Jun 9, 2023
Arbitrary file read using percent-encoded relative paths in FileMiddleware
Moderate
CVE-2020-15230
was published
for
github.com/vapor/vapor
(Swift)
Jun 9, 2023
hawtio vulnerable to Path Traversal
Moderate
CVE-2023-33544
was published
for
io.hawt:project
(Maven)
Jun 1, 2023
Starlette has Path Traversal vulnerability in StaticFiles
Moderate
CVE-2023-29159
was published
for
starlette
(pip)
May 17, 2023
Jenkins Code Dx Plugin missing permission checks
Moderate
CVE-2023-2196
was published
for
org.jenkins-ci.plugins:codedx
(Maven)
May 16, 2023
Jenkins Sidebar Link Plugin vulnerable to Path Traversal
Moderate
CVE-2023-32985
was published
for
org.jenkins-ci.plugins:sidebar-link
(Maven)
May 16, 2023
n8n Directory Traversal vulnerability
Moderate
CVE-2023-27562
was published
for
n8n
(npm)
May 10, 2023
Pimcore Path Traversal Vulnerability in AdminBundle/Controller/Reports/CustomReportController.php
Moderate
CVE-2023-30855
was published
for
pimcore/pimcore
(Composer)
May 2, 2023
Arbitrary File Read in Admin JS CSS files
Moderate
CVE-2023-30852
was published
for
pimcore/pimcore
(Composer)
Apr 27, 2023
Path Traversal in Asset "import from server" option
Moderate
CVE-2023-2336
was published
for
pimcore/pimcore
(Composer)
Apr 27, 2023
pretalx allows path traversal in HTML export
Moderate
CVE-2023-28458
was published
for
pretalx
(pip)
Apr 20, 2023
Path traversal vulnerability in gatsby-plugin-sharp
Moderate
CVE-2023-30548
was published
for
gatsby-plugin-sharp
(npm)
Apr 20, 2023
Arbitrary file write in mindsdb when Extracting Tarballs retrieved from a remote location
Moderate
CVE-2022-23522
was published
for
mindsdb
(pip)
Mar 30, 2023
pgAdmin 4 vulnerable to directory traversal
Moderate
CVE-2023-0241
was published
for
pgadmin4
(pip)
Mar 27, 2023
tripleo-ansible may disclose important configuration details from an OpenStack deployment
Moderate
CVE-2022-3101
was published
for
tripleo-ansible
(pip)
Mar 23, 2023
tripleo-ansible may disclose important configuration details from an OpenStack deployment
Moderate
CVE-2022-3146
was published
for
tripleo-ansible
(pip)
Mar 23, 2023
ProTip!
Advisories are also available from the
GraphQL API