GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
331 advisories
Filter by severity
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
High
GHSA-mr34-9552-qr95
was published
for
openclaw
(npm)
Apr 17, 2026
Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath
Moderate
GHSA-3pw3-v88x-xj24
was published
for
@paperclipai/shared
(npm)
Apr 16, 2026
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an...
High
Unreviewed
CVE-2026-39907
was published
Apr 15, 2026
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to...
High
Unreviewed
CVE-2026-5809
was published
Apr 11, 2026
NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability...
High
Unreviewed
CVE-2026-5053
was published
Apr 11, 2026
NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2026-5054
was published
Apr 11, 2026
Rembg has a Path Traversal via Custom Model Loading
Moderate
CVE-2026-40086
was published
for
rembg
(pip)
Apr 10, 2026
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
High
GHSA-qmwh-9m9c-h36m
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 7, 2026
Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT...
High
Unreviewed
CVE-2025-65115
was published
Apr 7, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
High
CVE-2026-34783
was published
for
github.com/MontFerret/ferret
(Go)
Apr 1, 2026
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
High
CVE-2026-34522
was published
for
sillytavern
(npm)
Apr 1, 2026
An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5...
High
Unreviewed
CVE-2026-30291
was published
Apr 1, 2026
An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows...
High
Unreviewed
CVE-2026-30292
was published
Apr 1, 2026
An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod...
High
Unreviewed
CVE-2026-30289
was published
Apr 1, 2026
An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4...
High
Unreviewed
CVE-2026-30287
was published
Apr 1, 2026
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate...
High
Unreviewed
CVE-2026-23898
was published
Apr 1, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
High
CVE-2026-30940
was published
for
baserproject/basercms
(Composer)
Mar 31, 2026
A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an...
Moderate
Unreviewed
CVE-2026-5210
was published
Mar 31, 2026
An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to...
High
Unreviewed
CVE-2026-30284
was published
Mar 31, 2026
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite...
Critical
Unreviewed
CVE-2026-30281
was published
Mar 31, 2026
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers...
Critical
Unreviewed
CVE-2026-30276
was published
Mar 31, 2026
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
High
CVE-2026-33949
was published
for
@tinacms/graphql
(npm)
Mar 30, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation
Moderate
CVE-2026-33027
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
High
CVE-2026-33989
was published
for
@mobilenext/mobile-mcp
(npm)
Mar 27, 2026
A flaw was found in libssh where it can attempt to open arbitrary files during configuration...
Low
Unreviewed
CVE-2026-0965
was published
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API