GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,891
Erlang
24
GitHub Actions
39
Go
2,240
Maven
2,698
npm
2,899
NuGet
500
pip
2,728
Pub
5
RubyGems
364
Rust
889
Swift
19
Unreviewed advisories
All unreviewed
5,000+
246 advisories
Filter by severity
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities...
High
Unreviewed
CVE-2026-26157
was published
Feb 11, 2026
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform...
Low
Unreviewed
CVE-2026-21249
was published
Feb 10, 2026
qdrant has arbitrary file write via `/logger` endpoint
High
CVE-2026-25628
was published
for
qdrant
(Rust)
Feb 5, 2026
survey-pdf Upgraded jsPDF Version Due to Security Vulnerability
Critical
CVE-2026-25630
was published
for
survey-pdf
(npm)
Feb 4, 2026
An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95...
Moderate
Unreviewed
CVE-2025-69621
was published
Feb 4, 2026
i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that...
High
Unreviewed
CVE-2020-37078
was published
Feb 4, 2026
webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration...
High
Unreviewed
CVE-2020-37080
was published
Feb 4, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
Critical
CVE-2025-64712
was published
for
unstructured
(pip)
Feb 3, 2026
H2O has an External Control of File Name or Path vulnerability
Critical
CVE-2024-5986
was published
for
ai.h2o:h2o-core
(Maven)
Feb 2, 2026
LobeHub Vulnerable to Improper Authorization in Presigned Upload
Moderate
CVE-2026-23835
was published
for
@lobehub/chat
(npm)
Feb 1, 2026
Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows...
High
Unreviewed
CVE-2021-47871
was published
Jan 21, 2026
NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows...
High
Unreviewed
CVE-2021-47746
was published
Jan 21, 2026
An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS...
Critical
Unreviewed
CVE-2025-53912
was published
Jan 20, 2026
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform...
Moderate
Unreviewed
CVE-2026-20925
was published
Jan 13, 2026
External control of file name or path in Windows Telephony Service allows an authorized attacker...
High
Unreviewed
CVE-2026-20931
was published
Jan 13, 2026
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform...
Moderate
Unreviewed
CVE-2026-20872
was published
Jan 13, 2026
An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a...
High
Unreviewed
CVE-2025-66003
was published
Jan 8, 2026
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all...
Moderate
Unreviewed
CVE-2025-14059
was published
Jan 7, 2026
jsPDF has Local File Inclusion/Path Traversal vulnerability
Critical
CVE-2025-68428
was published
for
jspdf
(npm)
Jan 5, 2026
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid...
High
Unreviewed
CVE-2025-62842
was published
Jan 2, 2026
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to...
Low
Unreviewed
CVE-2025-12654
was published
Dec 21, 2025
External Control of File Name or Path in Langflow
High
CVE-2025-68478
was published
for
langflow
(pip)
Dec 19, 2025
@vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint
High
CVE-2025-68155
was published
for
@vitejs/plugin-rsc
(npm)
Dec 16, 2025
The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions...
Moderate
Unreviewed
CVE-2025-13320
was published
Dec 12, 2025
An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6...
Critical
Unreviewed
CVE-2025-65473
was published
Dec 11, 2025
ProTip!
Advisories are also available from the
GraphQL API