GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,163
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,351 advisories
Filter by severity
Arbitrary Code Execution via Crafted Keras Config for Model Loading
High
CVE-2025-1550
was published
for
keras
(pip)
Mar 11, 2025
Duplicate Advisory: Keras arbitrary code execution vulnerability
High
GHSA-5478-v2w6-c6q7
was published
for
keras
(pip)
Mar 11, 2025
•
withdrawn
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
High
CVE-2025-25362
was published
for
spacy-llm
(pip)
Mar 5, 2025
dmlc/dgl Vulnerable to Remote Code Execution by Pickle Deserialization via rpc.recv_request()
High
GHSA-3x5x-fw77-g54c
was published
for
dgl
(pip)
Mar 5, 2025
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
High
CVE-2025-27154
was published
for
spotipy
(pip)
Feb 28, 2025
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
High
CVE-2025-1403
was published
for
qiskit
(pip)
Feb 21, 2025
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
High
CVE-2025-25305
was published
for
homeassistant
(pip)
Feb 18, 2025
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
High
CVE-2025-25297
was published
for
label-studio
(pip)
Feb 14, 2025
Label Studio has a Path Traversal Vulnerability via image Field
High
CVE-2025-25295
was published
for
label-studio-sdk
(pip)
Feb 14, 2025
Mitmweb API Authentication Bypass Using Proxy Server
High
CVE-2025-23217
was published
for
mitmproxy
(pip)
Feb 6, 2025
MobSF Stored Cross-Site Scripting (XSS)
High
CVE-2025-24803
was published
for
mobsf
(pip)
Feb 5, 2025
CKAN has an XSS vector in user uploaded images in group/org and user profiles
High
CVE-2025-24372
was published
for
ckan
(pip)
Feb 5, 2025
snowflake-connector-python vulnerable to SQL Injection in write_pandas
High
CVE-2025-24793
was published
for
snowflake-connector-python
(pip)
Jan 29, 2025
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
High
CVE-2025-24357
was published
for
vllm
(pip)
Jan 27, 2025
uniapi version 1.0.7 contained an information harvesting script.
High
GHSA-gvvw-rr8m-fj76
was published
for
uniapi
(pip)
Jan 27, 2025
ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape
High
CVE-2025-24359
was published
for
asteval
(pip)
Jan 24, 2025
ASTEVAL Allows Malicious Tampering of Exposed AST Nodes Leads to Sandbox Escape
High
GHSA-vp47-9734-prjw
was published
for
asteval
(pip)
Jan 23, 2025
try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
High
CVE-2025-22153
was published
for
RestrictedPython
(pip)
Jan 23, 2025
sniff_csv provides filesystem access even when enable_external_access is disabled in duckdb
High
CVE-2024-41672
was published
for
duckdb
(pip)
Jan 21, 2025
Cross-Site Request Forgery in CodeChecker API
High
CVE-2024-53829
was published
for
codechecker
(pip)
Jan 21, 2025
nbgrader's `frame-ancestors: self` grants all users access to formgrader
High
CVE-2025-23205
was published
for
nbgrader
(pip)
Jan 17, 2025
pgAdmin has Incorrect Default Permissions
High
CVE-2023-1907
was published
for
pgadmin4
(pip)
Jan 9, 2025
ProTip!
Advisories are also available from the
GraphQL API