GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,238
Erlang
31
GitHub Actions
21
Go
2,005
Maven
5,000+
npm
3,716
NuGet
661
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
359 advisories
Filter by severity
moby Access to remapped root allows privilege escalation to real root
Moderate
CVE-2021-21284
was published
for
github.com/moby/moby
(Go)
Jan 31, 2024
Path Traversal in Moby builder
Moderate
CVE-2020-27534
was published
for
github.com/docker/docker
(Go)
Jan 31, 2024
Grafana Arbitrary File Read
Moderate
CVE-2019-19499
was published
for
github.com/grafana/grafana
(Go)
Jan 31, 2024
stereoscope vulnerable to tar path traversal when processing OCI tar archives
Moderate
CVE-2024-24579
was published
for
github.com/anchore/stereoscope
(Go)
Jan 31, 2024
CrateDB database has an arbitrary file read vulnerability
Moderate
CVE-2024-24565
was published
for
io.crate:crate
(Maven)
Jan 30, 2024
Path traversal vulnerability in Jenkins Matrix Project Plugin
Moderate
CVE-2024-23900
was published
for
org.jenkins-ci.plugins:matrix-project
(Maven)
Jan 24, 2024
@hono/node-server cannot handle "double dots" in URL
Moderate
CVE-2024-23340
was published
for
@hono/node-server
(npm)
Jan 23, 2024
Apache Shiro vulnerable to path traversal
Moderate
CVE-2023-46749
was published
for
org.apache.shiro:shiro-core
(Maven)
Jan 15, 2024
Ansible symlink attack vulnerability
Moderate
CVE-2023-5115
was published
for
ansible
(pip)
Dec 28, 2023
Duplicate Advisory: TYPO3 Arbitrary File Read via Directory Traversal
Moderate
GHSA-3gjc-mp82-fj4q
was published
for
typo3/cms-core
(Composer)
Dec 25, 2023
•
withdrawn
Potential URI resolution path traversal in the AWS SDK for PHP
Moderate
CVE-2023-51651
was published
for
aws/aws-sdk-php
(Composer)
Dec 21, 2023
Directory Traversal in evershop
Moderate
CVE-2023-46497
was published
for
@evershop/evershop
(npm)
Dec 8, 2023
Directory Traversal in evershop
Moderate
CVE-2023-46493
was published
for
@evershop/evershop
(npm)
Dec 8, 2023
Directory Traversal in Gladys Assistant
Moderate
CVE-2023-47440
was published
for
gladys
(npm)
Dec 7, 2023
Directory Traversal in jeecg-boot
Moderate
CVE-2023-47467
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Nov 22, 2023
Ansible galaxy-importer Path Traversal vulnerability
Moderate
CVE-2023-5189
was published
for
galaxy-importer
(pip)
Nov 15, 2023
baserCMS Directory Traversal vulnerability in Form submission data management Feature
Moderate
CVE-2023-43648
was published
for
baserproject/basercms
(Composer)
Oct 26, 2023
Jenkins CloudBees CD Plugin vulnerable to arbitrary file read
Moderate
CVE-2023-46655
was published
for
org.jenkins-ci.plugins:electricflow
(Maven)
Oct 25, 2023
Wagtail CRX CodeRed Extensions vulnerable to Path Traversal
Moderate
CVE-2021-46897
was published
for
coderedcms
(pip)
Oct 22, 2023
Arduino Create Agent path traversal - arbitrary file deletion vulnerability
Moderate
CVE-2023-43803
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
Arduino Create Agent path traversal - arbitrary file deletion vulnerability
Moderate
CVE-2023-43801
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
Moderate
CVE-2023-40026
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 27, 2023
Sender can cause a receiver to overwrite files during ZIP extraction in Croc
Moderate
CVE-2023-43616
was published
for
github.com/schollz/croc
(Go)
Sep 20, 2023
Terraform allows arbitrary file write during the `init` operation
Moderate
CVE-2023-4782
was published
for
github.com/hashicorp/terraform
(Go)
Sep 8, 2023
ProTip!
Advisories are also available from the
GraphQL API