GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
9,925 advisories
Filter by severity
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Moderate
GHSA-p23f-cm6q-2qp8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Vibe-Trading file-read tools expose arbitrary server-readable files
High
GHSA-5rmq-chc7-m22f
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11...
High
Unreviewed
CVE-2014-125130
was published
Oct 2, 2026
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
Moderate
CVE-2026-59944
was published
for
composer/composer
(Composer)
Oct 2, 2026
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
High
GHSA-8mcx-5rqc-vhmf
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
High
GHSA-5fqc-mrg8-w798
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
High
GHSA-cm62-gvxx-vmxx
was published
for
dulwich
(pip)
Oct 2, 2026
In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal...
High
Unreviewed
CVE-2026-51907
was published
Oct 2, 2026
Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to...
Critical
Unreviewed
CVE-2026-103648
was published
Oct 2, 2026
Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module)...
Moderate
Unreviewed
CVE-2026-104721
was published
Oct 2, 2026
Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows...
High
Unreviewed
CVE-2026-104418
was published
Oct 2, 2026
Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file...
Moderate
Unreviewed
CVE-2026-104417
was published
Oct 2, 2026
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows...
High
Unreviewed
CVE-2025-71427
was published
Oct 2, 2026
Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 ...
Critical
Unreviewed
CVE-2026-55393
was published
Oct 1, 2026
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability...
Critical
Unreviewed
CVE-2026-104286
was published
Oct 1, 2026
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution...
Moderate
Unreviewed
CVE-2026-103884
was published
Oct 1, 2026
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal...
High
Unreviewed
CVE-2026-101888
was published
Oct 1, 2026
The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that...
High
Unreviewed
CVE-2026-101889
was published
Oct 1, 2026
Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.
High
Unreviewed
CVE-2026-95588
was published
Oct 1, 2026
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file...
High
Unreviewed
CVE-2024-58388
was published
Oct 1, 2026
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Moderate
CVE-2026-92945
was published
for
vm2
(npm)
Oct 1, 2026
A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a...
Moderate
Unreviewed
CVE-2026-103754
was published
Oct 1, 2026
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a...
High
Unreviewed
CVE-2026-103254
was published
Oct 1, 2026
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a...
High
Unreviewed
CVE-2026-103257
was published
Oct 1, 2026
A path traversal vulnerability exists in the web management interface of multiple Multifunction...
Moderate
Unreviewed
CVE-2026-78249
was published
Oct 1, 2026
ProTip!
Advisories are also available from the
GraphQL API