GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,163
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,435 advisories
Filter by severity
Rembg allows SSRF via /api/remove
Moderate
CVE-2025-25301
was published
for
rembg
(pip)
Mar 11, 2025
Azure PromptFlow remote code execution related to Jinja templates
Moderate
CVE-2025-24986
was published
for
promptflow-core
(pip)
Mar 11, 2025
Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1944
was published
for
picklescan
(pip)
Mar 10, 2025
Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1945
was published
for
picklescan
(pip)
Mar 10, 2025
Duplicate Advisory: Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-2fh4-gpch-vqv4
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Duplicate Advisory: Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-w6mr-mj53-x258
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Django vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2025-26699
was published
for
Django
(pip)
Mar 6, 2025
ray vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-1979
was published
for
ray
(pip)
Mar 6, 2025
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Moderate
CVE-2025-27516
was published
for
Jinja2
(pip)
Mar 5, 2025
Duplicate Advisory: Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
GHSA-hw34-rqc5-h2gm
was published
for
picklescan
(pip)
Mar 3, 2025
•
withdrawn
Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
CVE-2025-1716
was published
for
picklescan
(pip)
Mar 3, 2025
PyTorch Model Files Can Bypass Pickle Scanners via Unexpected Pickle Extensions
Moderate
CVE-2025-1889
was published
for
picklescan
(pip)
Mar 3, 2025
CodeChecker open redirect when URL contains multiple slashes after the product name
Moderate
CVE-2025-1300
was published
for
codechecker
(pip)
Mar 3, 2025
Duplicate Advisory: Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
GHSA-vr75-hjh9-7fr6
was published
for
picklescan
(pip)
Mar 3, 2025
•
withdrawn
Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0
Moderate
CVE-2025-1057
was published
for
keylime
(pip)
Feb 14, 2025
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
Moderate
CVE-2025-25296
was published
for
label-studio
(pip)
Feb 14, 2025
xml2rfc has file inclusion irregularities
Moderate
GHSA-432c-wxpg-m4q3
was published
for
xml2rfc
(pip)
Feb 7, 2025
snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
Moderate
CVE-2025-24794
was published
for
snowflake-connector-python
(pip)
Jan 29, 2025
snowflake-connector-python vulnerable to insecure cache files permissions
Moderate
CVE-2025-24795
was published
for
snowflake-connector-python
(pip)
Jan 29, 2025
Django has a potential denial-of-service vulnerability in IPv6 validation
Moderate
CVE-2024-56374
was published
for
Django
(pip)
Jan 14, 2025
Composio Command Execution vulnerability
Moderate
CVE-2024-53526
was published
for
composio-claude
(pip)
Jan 8, 2025
keras Path Traversal vulnerability
Moderate
CVE-2024-55459
was published
for
keras
(pip)
Jan 8, 2025
khoj has an IDOR in subscription management allows unauthorized subscription modifications
Moderate
CVE-2024-52294
was published
for
khoj
(pip)
Dec 30, 2024
ProTip!
Advisories are also available from the
GraphQL API