GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,003
Maven
5,000+
npm
4,732
NuGet
788
pip
4,341
Pub
12
RubyGems
987
Rust
1,137
Swift
50
Unreviewed advisories
All unreviewed
5,000+
133 advisories
Filter by severity
FUXA contains an Unrestricted File Upload vulnerability
High
CVE-2025-69981
was published
for
fuxa-server
(npm)
Feb 3, 2026
NocoDB Vulnerable to Stored Cross-Site Scripting via SVG upload
High
CVE-2026-24769
was published
for
nocodb
(npm)
Jan 28, 2026
Livewire Filemanager does not restrict uploaded file types
High
CVE-2025-14894
was published
for
livewire-filemanager/filemanager
(Composer)
Jan 16, 2026
Gin-vue-admin has arbitrary file upload vulnerability caused by path traversal
High
CVE-2026-22786
was published
for
github.com/flipped-aurora/gin-vue-admin
(Go)
Jan 13, 2026
Cadmium CMS has a background arbitrary file upload vulnerability
High
CVE-2025-51511
was published
for
cadmium-org/cadmium-cms
(Composer)
Dec 23, 2025
GrapesJsBuilder File Upload allows all file uploads
High
CVE-2025-13827
was published
for
mautic/grapes-js-builder-bundle
(Composer)
Dec 2, 2025
FlowiseAI/Flosise has File Upload vulnerability
High
CVE-2025-61687
was published
for
flowise
(npm)
Oct 8, 2025
N8N's Chat Trigger component is vulnerable to XSS
High
CVE-2025-56265
was published
for
@n8n/n8n-nodes-langchain
(npm)
Sep 8, 2025
Badaso CMS file upload vulnerability
High
CVE-2025-52353
was published
for
badaso/core
(Composer)
Aug 26, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
CVE-2025-55743
was published
for
unopim/unopim
(Composer)
Aug 21, 2025
Juju allows arbitrary executable uploads via authenticated endpoint without authorization
High
CVE-2025-0928
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE
High
GHSA-gj54-gwj9-x2c6
was published
for
github.com/lf-edge/ekuiper
(Go)
Jul 3, 2025
youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization
High
GHSA-22fp-mf44-f2mq
was published
for
youtube-dl
(pip)
Apr 18, 2025
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
High
CVE-2024-8060
was published
for
open-webui
(pip)
Mar 20, 2025
FlowiseAI Flowise arbitrary file upload vulnerability
High
CVE-2025-26319
was published
for
flowise
(npm)
Mar 5, 2025
Cockpit Arbitrary File Upload
High
CVE-2025-1025
was published
for
cockpit-hq/cockpit
(Composer)
Feb 5, 2025
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
High
CVE-2024-53863
was published
for
matrix-synapse
(pip)
Dec 3, 2024
Livewire Remote Code Execution on File Uploads
High
CVE-2024-47823
was published
for
livewire/livewire
(Composer)
Oct 8, 2024
Contao affected by remote command execution through file upload
High
CVE-2024-45398
was published
for
contao/core-bundle
(Composer)
Sep 17, 2024
Automad arbitrary file upload vulnerability
High
CVE-2024-40400
was published
for
automad/automad
(Composer)
Jul 19, 2024
Apache StreamPipes has potential remote code execution (RCE) via file upload
High
CVE-2024-31411
was published
for
org.apache.streampipes:streampipes-parent
(Maven)
Jul 17, 2024
yt-dlp File system modification and RCE through improper file-extension sanitization
High
CVE-2024-38519
was published
for
yt-dlp
(pip)
Jul 2, 2024
Dolibarr arbitrary file upload vulnerability
High
CVE-2024-37821
was published
for
dolibarr/dolibarr
(Composer)
Jun 18, 2024
Duplicate Advisory: aimeos-core arbitrary file upload vulnerability
High
CVE-2024-36811
was published
for
aimeos/aimeos-core
(Composer)
Jun 7, 2024
•
withdrawn
TYPO3 Arbitrary Code Execution via File List Module
High
GHSA-8h4m-r4wm-xj7r
was published
for
typo3/cms
(Composer)
Jun 7, 2024
ProTip!
Advisories are also available from the
GraphQL API