GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,358
Maven
5,000+
npm
3,979
NuGet
720
pip
3,777
Pub
12
RubyGems
924
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
313 advisories
Filter by severity
Path Traversal: 'dir/../../filename' in moment.locale
High
CVE-2022-24785
was published
for
Moment.js
(npm)
Apr 4, 2022
Path Traversal in @finastra/ssr-pages
High
CVE-2022-24718
was published
for
@finastra/ssr-pages
(npm)
Mar 1, 2022
Path Traversal in convert-svg packages
High
CVE-2021-23631
was published
for
convert-svg-core
(npm)
Jan 27, 2022
Path Traversal in http-server-node
High
CVE-2021-23797
was published
for
http-server-node
(npm)
Jan 5, 2022
Path Traversal in @backstage/plugin-scaffolder-backend
High
CVE-2021-43783
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Dec 1, 2021
NodeBB vulnerable to path traversal in translator module
Moderate
CVE-2021-43788
was published
for
nodebb
(npm)
Nov 30, 2021
Path Traversal in @backstage/plugin-scaffolder-backend
Moderate
CVE-2021-41151
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Oct 19, 2021
Path Traversal in serve-here.js
Moderate
CVE-2019-5444
was published
for
serve-here.js
(npm)
Sep 22, 2021
Directory Traversal in isomorphic-git
Moderate
CVE-2021-30483
was published
for
isomorphic-git
(npm)
Sep 2, 2021
Directory Traversal in startserver
High
CVE-2021-23430
was published
for
startserver
(npm)
Sep 2, 2021
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
High
CVE-2021-37701
was published
for
tar
(npm)
Aug 31, 2021
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
High
CVE-2021-37712
was published
for
tar
(npm)
Aug 31, 2021
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
High
CVE-2021-37713
was published
for
tar
(npm)
Aug 31, 2021
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
High
CVE-2021-32804
was published
for
tar
(npm)
Aug 3, 2021
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning
High
CVE-2021-32803
was published
for
tar
(npm)
Aug 3, 2021
Path traversal
Moderate
CVE-2021-32662
was published
for
@backstage/techdocs-common
(npm)
Jun 4, 2021
Path traversal in rollup-plugin-serve
Critical
CVE-2020-7684
was published
for
rollup-plugin-serve
(npm)
May 18, 2021
Path Traversal in browserless-chrome
High
CVE-2020-7758
was published
for
browserless-chrome
(npm)
May 10, 2021
ProTip!
Advisories are also available from the
GraphQL API