GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,617
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            14 advisories
        Filter by severity
        
      
      
    
                    
                      Dpanel has an arbitrary file read vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53363
                      
                      was published
                        for
                        
                          github.com/donknap/dpanel
                        
                        (Go)
                      Aug 22, 2025 
                    
                  
                    
                      Salt's file contents overwrite the VirtKey class
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-22241
                      
                      was published
                        for
                        
                          salt
                        
                        (pip)
                      Jun 13, 2025 
                    
                  
                    
                      OctoPrint vulnerable to possible file extraction via upload endpoints
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48067
                      
                      was published
                        for
                        
                          OctoPrint
                        
                        (pip)
                      Jun 10, 2025 
                    
                  
                    
                      HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-49138
                      
                      was published
                        for
                        
                          elmsln/haxcms
                        
                        (Composer)
                      Jun 9, 2025 
                    
                  
                    
                      Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-10492
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-quarkus-server
                        
                        (Maven)
                      Nov 25, 2024 
                    
                  
                    
                      GeoServer Arbitrary file renaming vulnerability in REST Coverage/Data Store API
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-23634
                      
                      was published
                        for
                        
                          org.geoserver:gs-restconfig
                        
                        (Maven)
                      Mar 20, 2024 
                    
                  
                    
                      php-svg-lib lacks path validation on font through SVG inline styles 
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-25117
                      
                      was published
                        for
                        
                          phenx/php-svg-lib
                        
                        (Composer)
                      Feb 21, 2024 
                    
                  
                    
                      Moodle External Control of File Name or Path vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-30943
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 2, 2023 
                    
                  
                    
                      Juju controller - Arbitrary file reading vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-0092
                      
                      was published
                        for
                        
                          github.com/juju/juju
                        
                        (Go)
                      Mar 1, 2023 
                    
                  
                    
                      Cortex's Alertmanager can expose local files content via specially crafted config
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-23536
                      
                      was published
                        for
                        
                          github.com/cortexproject/cortex
                        
                        (Go)
                      Dec 19, 2022 
                    
                  
                    
                      Dompdf before v2.0.0 vulnerable to chroot check bypass
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-2400
                      
                      was published
                        for
                        
                          dompdf/dompdf
                        
                        (Composer)
                      Jul 19, 2022 
                    
                  
                    
                      ingress-nginx component for Kubernetes allows file overwrite
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-8553
                      
                      was published
                        for
                        
                          k8s.io/ingress-nginx
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21343
                      
                      was published
                        for
                        
                          com.thoughtworks.xstream:xstream
                        
                        (Maven)
                      Mar 22, 2021 
                    
                  
                    
                      Arbitrary File Deletion vulnerability in OctoberCMS
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-5296
                      
                      was published
                        for
                        
                          october/cms
                        
                        (Composer)
                      Jun 3, 2020 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API