GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
58 advisories
Filter by severity
A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include...
Moderate
Unreviewed
CVE-2024-8982
was published
Mar 20, 2025
MLflow has a Local File Read/Path Traversal in dbfs
High
CVE-2024-8859
was published
for
mlflow
(pip)
Mar 20, 2025
A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041...
High
Unreviewed
CVE-2024-8248
was published
Mar 20, 2025
AgentScope path traversal vulnerability
Critical
CVE-2024-8537
was published
for
agentscope
(pip)
Mar 20, 2025
Aim path traversal in LockManager.release_locks
Critical
CVE-2024-8769
was published
for
aim
(pip)
Mar 20, 2025
An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer,...
Critical
Unreviewed
CVE-2024-7957
was published
Mar 20, 2025
Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint
Moderate
CVE-2024-7033
was published
for
open-webui
(pip)
Mar 20, 2025
A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The...
High
Unreviewed
CVE-2024-12389
was published
Mar 20, 2025
A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to...
High
Unreviewed
CVE-2024-11170
was published
Mar 20, 2025
Gradio Vulnerable to Arbitrary File Deletion
High
CVE-2024-10648
was published
for
gradio
(pip)
Mar 20, 2025
A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal...
High
Unreviewed
CVE-2024-13059
was published
Feb 10, 2025
Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path...
High
Unreviewed
CVE-2024-51534
was published
Feb 1, 2025
luigi Arbitrary File Write via Archive Extraction (Zip Slip)
High
CVE-2024-21542
was published
for
luigi
(pip)
Dec 10, 2024
Langchain Path Traversal vulnerability
Moderate
CVE-2024-7774
was published
for
langchain
(npm)
Oct 29, 2024
An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to...
High
Unreviewed
CVE-2024-7962
was published
Oct 29, 2024
A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The...
High
Unreviewed
CVE-2024-6394
was published
Sep 30, 2024
Path Traversal: '\..\filename' in aimhubio/aim
Critical
Unreviewed
CVE-2024-6396
was published
Jul 12, 2024
Path Traversal: '\..\filename' in GitHub repository stitionai/devika prior to -.
Critical
Unreviewed
CVE-2024-5926
was published
Jun 30, 2024
lollms vulnerable to dot-dot-slash path traversal in XTTS server
High
CVE-2024-6139
was published
for
lollms
(pip)
Jun 27, 2024
A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the ...
Moderate
Unreviewed
CVE-2024-4841
was published
Jun 23, 2024
Remote Code Execution via path traversal bypass in lollms
Critical
CVE-2024-5443
was published
for
lollms
(pip)
Jun 22, 2024
Zip slip in opencart
High
CVE-2024-21518
was published
for
opencart/opencart
(Composer)
Jun 22, 2024
A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the ...
Critical
Unreviewed
CVE-2024-5211
was published
Jun 12, 2024
A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the...
Critical
Unreviewed
CVE-2024-4320
was published
Jun 6, 2024
ProTip!
Advisories are also available from the
GraphQL API