GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
9,006 advisories
Filter by severity
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the...
High
Unreviewed
CVE-2026-13186
was published
Jul 22, 2026
Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an...
High
Unreviewed
CVE-2026-65600
was published
Jul 22, 2026
A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This...
Moderate
Unreviewed
CVE-2026-44192
was published
Jul 22, 2026
A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a...
High
Unreviewed
CVE-2026-56844
was published
Jul 22, 2026
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker...
High
Unreviewed
CVE-2026-50757
was published
Jul 21, 2026
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
Critical
GHSA-p63j-vcc4-9vmv
was published
for
@vitest/browser
(npm)
Jul 21, 2026
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows...
Critical
Unreviewed
CVE-2026-64825
was published
Jul 21, 2026
Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore...
Critical
Unreviewed
CVE-2026-64824
was published
Jul 21, 2026
Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
Moderate
GHSA-frvp-7c67-39w9
was published
for
@hono/node-server
(npm)
Jul 21, 2026
The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe...
Moderate
Unreviewed
CVE-2026-13693
was published
Jul 21, 2026
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
Moderate
CVE-2026-62843
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
Moderate
CVE-2026-59946
was published
for
composer/composer
(Composer)
Jul 20, 2026
Mistune: Arbitrary File Read via Include directive path traversal
Moderate
CVE-2026-59924
was published
for
mistune
(pip)
Jul 20, 2026
Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java...
High
Unreviewed
CVE-2026-56623
was published
Jul 20, 2026
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library...
High
Unreviewed
CVE-2026-56452
was published
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via...
High
Unreviewed
CVE-2026-60027
was published
Jul 20, 2026
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
Moderate
CVE-2026-55668
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
High
CVE-2026-55667
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Composer: Arbitrary file write outside vendor via malicious transitive package name
High
CVE-2026-59948
was published
for
composer/composer
(Composer)
Jul 20, 2026
changedetection.io is vulnerable to unauthenticated static path traversal
Moderate
CVE-2026-25527
was published
for
changedetection.io
(pip)
Jul 20, 2026
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only...
Critical
Unreviewed
CVE-2026-12701
was published
Jul 20, 2026
Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit...
High
Unreviewed
CVE-2026-52349
was published
Jul 20, 2026
SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER...
High
Unreviewed
CVE-2026-63739
was published
Jul 20, 2026
The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a...
Moderate
Unreviewed
CVE-2026-12898
was published
Jul 20, 2026
A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager:...
Low
Unreviewed
CVE-2026-16219
was published
Jul 19, 2026
ProTip!
Advisories are also available from the
GraphQL API