GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
911
pip
4,760
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
3,483 advisories
Filter by severity
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to...
Moderate
Unreviewed
CVE-2026-20148
was published
Apr 15, 2026
WWBN AVideo has an Incomplete fix: Directory traversal bypass via query string in ReceiveImage downloadURL parameters
Moderate
GHSA-m63r-m9jh-3vc6
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has an incomplete fix for CVE-2026-33293: Path Traversal
Moderate
GHSA-5879-4fmr-xwf2
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in...
Moderate
Unreviewed
CVE-2026-25691
was published
Apr 14, 2026
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
Moderate
Unreviewed
CVE-2026-2399
was published
Apr 14, 2026
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability...
Moderate
Unreviewed
CVE-2026-22573
was published
Apr 14, 2026
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability...
Moderate
Unreviewed
CVE-2025-68649
was published
Apr 14, 2026
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22]...
Moderate
Unreviewed
CVE-2025-61624
was published
Apr 14, 2026
Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
Moderate
CVE-2026-33929
was published
for
org.apache.pdfbox:pdfbox-examples
(Maven)
Apr 14, 2026
gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall
Moderate
CVE-2026-40491
was published
for
gdown
(pip)
Apr 14, 2026
OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2026-3689
was published
Apr 11, 2026
Rembg has a Path Traversal via Custom Model Loading
Moderate
CVE-2026-40086
was published
for
rembg
(pip)
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
Moderate
GHSA-vj8v-p5vw-m6v5
was published
for
xrootd
(pip)
Apr 10, 2026
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
Moderate
CVE-2026-40152
was published
for
praisonaiagents
(pip)
Apr 10, 2026
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Moderate
CVE-2026-35206
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2026
A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function...
Moderate
Unreviewed
CVE-2026-6024
was published
Apr 10, 2026
A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the...
Moderate
Unreviewed
CVE-2026-5998
was published
Apr 10, 2026
A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function...
Moderate
Unreviewed
CVE-2026-5962
was published
Apr 9, 2026
A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown...
Moderate
Unreviewed
CVE-2026-5849
was published
Apr 9, 2026
A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function...
Moderate
Unreviewed
CVE-2026-5841
was published
Apr 9, 2026
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
Moderate
GHSA-766v-q9x3-g744
was published
for
praisonaiagents
(pip)
Apr 8, 2026
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class
Moderate
CVE-2026-40180
was published
for
io.quarkiverse.openapi.generator:quarkus-openapi-generator
(Maven)
Apr 8, 2026
LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read
Moderate
CVE-2026-39859
was published
for
liquidjs
(npm)
Apr 8, 2026
NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows
Moderate
CVE-2026-39844
was published
for
nicegui
(pip)
Apr 8, 2026
Hono: Path traversal in toSSG() allows writing files outside the output directory
Moderate
CVE-2026-39408
was published
for
hono
(npm)
Apr 8, 2026
ProTip!
Advisories are also available from the
GraphQL API