GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
10,039 advisories
Filter by severity
The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in...
Moderate
Unreviewed
CVE-2026-104763
was published
Oct 10, 2026
Shiny for Python has path traversal in bookmark restore
Moderate
CVE-2026-108258
was published
for
shiny
(pip)
Oct 9, 2026
Contao: Path traversal in the images controller
Moderate
CVE-2026-107844
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard...
High
Unreviewed
CVE-2026-108158
was published
Oct 9, 2026
pyLoad: Tar extraction creates device nodes and FIFOs (member types not filtered; tarfile extractall without filter=)
High
GHSA-fr26-jjhm-638c
was published
for
pyload-ng
(pip)
Oct 9, 2026
KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function...
High
Unreviewed
CVE-2026-104081
was published
Oct 9, 2026
Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in...
High
Unreviewed
CVE-2026-103412
was published
Oct 9, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2026-94664
was published
Oct 9, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2026-94666
was published
Oct 9, 2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an...
Moderate
Unreviewed
CVE-2026-78340
was published
Oct 9, 2026
A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor...
Critical
Unreviewed
CVE-2026-107935
was published
Oct 9, 2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to cause a denial...
High
Unreviewed
CVE-2026-84247
was published
Oct 9, 2026
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute...
Critical
Unreviewed
CVE-2026-75875
was published
Oct 9, 2026
IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to delete arbitrary...
High
Unreviewed
CVE-2026-82900
was published
Oct 9, 2026
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry
Moderate
CVE-2026-107716
was published
for
banks
(pip)
Oct 8, 2026
PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
Critical
CVE-2026-61445
was published
for
praisonai
(pip)
Oct 8, 2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0...
High
Unreviewed
CVE-2026-19493
was published
Oct 8, 2026
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload...
High
Unreviewed
CVE-2026-84275
was published
Oct 8, 2026
A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The...
High
Unreviewed
CVE-2026-107709
was published
Oct 8, 2026
HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable...
Moderate
Unreviewed
CVE-2026-19585
was published
Oct 8, 2026
PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
Moderate
CVE-2026-61431
was published
for
praisonai
(pip)
Oct 8, 2026
datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory
High
CVE-2026-107377
was published
for
datamodel-code-generator
(pip)
Oct 8, 2026
PraisonAI: Project custom command templates can read outside-workspace files into model prompts
Moderate
CVE-2026-60088
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
High
CVE-2026-61443
was published
for
praisonaiagents
(pip)
Oct 8, 2026
PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
Moderate
CVE-2026-61432
was published
for
praisonaiagents
(pip)
Oct 8, 2026
ProTip!
Advisories are also available from the
GraphQL API