GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
183 advisories
Filter by severity
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low...
Low
Unreviewed
CVE-2026-56089
was published
Aug 17, 2026
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low...
High
Unreviewed
CVE-2026-59909
was published
Aug 17, 2026
Subscriber Path Traversal in Do Lasso <= 358 versions.
High
Unreviewed
CVE-2026-28157
was published
Aug 13, 2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The...
High
Unreviewed
CVE-2026-69109
was published
Aug 11, 2026
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote,...
Critical
Unreviewed
CVE-2026-13716
was published
Aug 11, 2026
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to...
Critical
Unreviewed
CVE-2026-59115
was published
Aug 7, 2026
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Moderate
Unreviewed
CVE-2026-66695
was published
Aug 6, 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal...
Moderate
Unreviewed
CVE-2025-59181
was published
Jul 27, 2026
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
High
Unreviewed
CVE-2025-60835
was published
Jul 22, 2026
Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 versions.
Moderate
Unreviewed
CVE-2026-49779
was published
Jul 2, 2026
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
Critical
GHSA-phv5-334h-mxcw
was published
for
motioneye
(pip)
Jun 23, 2026
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
High
Unreviewed
CVE-2026-52707
was published
Jun 17, 2026
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
High
Unreviewed
CVE-2026-49112
was published
Jun 15, 2026
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
Critical
Unreviewed
CVE-2026-52703
was published
Jun 15, 2026
Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.
High
Unreviewed
CVE-2026-42661
was published
Jun 15, 2026
SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service...
Moderate
Unreviewed
CVE-2026-24315
was published
Jun 9, 2026
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft...
Critical
Unreviewed
CVE-2026-40128
was published
Jun 9, 2026
A path traversal condition in Intrado 911 Emergency Gateway could allow an attacker with existing...
Critical
Unreviewed
CVE-2026-6074
was published
Apr 23, 2026
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
Critical
CVE-2026-7302
was published
for
sglang
(pip)
May 18, 2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
High
Unreviewed
CVE-2026-45495
was published
May 18, 2026
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently ...
High
Unreviewed
CVE-2026-44933
was published
May 20, 2026
The File Management System developed by FileOrbis before version 10.6.3 has an unauthenticated...
High
Unreviewed
CVE-2022-3693
was published
Jan 13, 2023
The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before...
High
Unreviewed
CVE-2022-2265
was published
Sep 22, 2022
Rancher Extensions have arbitrary file access via path traversal
High
CVE-2026-25705
was published
for
github.com/rancher/rancher
(Go)
May 7, 2026
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may...
High
Unreviewed
CVE-2026-42930
was published
May 13, 2026
ProTip!
Advisories are also available from the
GraphQL API