GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
23 advisories
Filter by severity
Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
High
CVE-2026-47243
was published
for
github.com/kata-containers/kata-containers
(Go)
May 27, 2026
Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability
High
CVE-2026-32175
was published
for
Microsoft.NetCore.App.Runtime.win-arm
(NuGet)
May 18, 2026
PyLoad vulnerable to Path Traversal via Package Folder Name in set_package_data
High
CVE-2026-42315
was published
for
pyload-ng
(pip)
May 5, 2026
AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
Moderate
CVE-2026-34515
was published
for
aiohttp
(pip)
Apr 1, 2026
NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
High
CVE-2026-0846
was published
for
nltk
(pip)
Mar 9, 2026
Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+
High
CVE-2026-28414
was published
for
gradio
(pip)
Mar 1, 2026
MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
High
CVE-2025-68472
was published
for
MindsDB
(pip)
Jan 12, 2026
MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827
Moderate
CVE-2025-67898
was published
for
mjml
(npm)
Dec 15, 2025
Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read
Moderate
GHSA-vffh-c9pq-4crh
was published
for
uptime-kuma
(npm)
Oct 20, 2025
Jenkins HTML Publisher Plugin vulnerability displays controller file system information in its logs
Moderate
CVE-2025-53651
was published
for
org.jenkins-ci.plugins:htmlpublisher
(Maven)
Jul 9, 2025
AgentScope arbitrary file download vulnerability in rpc_agent_client
High
CVE-2024-8501
was published
for
agentscope
(pip)
Mar 20, 2025
H2O Vulnerable to Arbitrary File Overwrite via File Export
High
CVE-2024-6854
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
Critical
CVE-2024-10833
was published
for
dbgpt
(pip)
Mar 20, 2025
DB-GPT Absolute Path Traversal vulnerability
Critical
CVE-2024-10831
was published
for
dbgpt
(pip)
Mar 20, 2025
Deep Java Library path traversal issue
Critical
CVE-2025-0851
was published
for
ai.djl:api
(Maven)
Jan 29, 2025
Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
Critical
CVE-2024-47883
was published
for
org.openrefine.dependencies:butterfly
(Maven)
Oct 24, 2024
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled
Moderate
CVE-2024-45291
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery when opening XLSX file
High
CVE-2024-45290
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
Ansible symlink attack vulnerability
Moderate
CVE-2023-5115
was published
for
ansible
(pip)
Dec 28, 2023
MLflow Path Traversal vulnerability
Critical
CVE-2023-3765
was published
for
mlflow
(pip)
Jul 19, 2023
Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs
Moderate
CVE-2023-1176
was published
for
mlflow
(pip)
Mar 24, 2023
Path Traversal in scout-browser
Moderate
CVE-2022-1554
was published
for
scout-browser
(pip)
May 4, 2022
ProTip!
Advisories are also available from the
GraphQL API