GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,481 advisories
Filter by severity
Withdrawn Advisory: ReDoS in py library when used with subversion
High
CVE-2022-42969
was published
for
py
(pip)
Oct 16, 2022
•
withdrawn
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
High
CVE-2025-30167
was published
for
jupyter_core
(pip)
Jun 4, 2025
OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size
High
CVE-2025-48071
was published
for
OpenEXR
(pip)
Jul 31, 2025
LangChain pickle deserialization of untrusted data
High
CVE-2024-5998
was published
for
langchain-community
(pip)
Sep 17, 2024
Minerva timing attack on P-256 in python-ecdsa
High
CVE-2024-23342
was published
for
ecdsa
(pip)
Jan 22, 2024
Bugsink path traversal via event_id in ingestion
High
CVE-2025-54433
was published
for
bugsink
(pip)
Jul 29, 2025
Apache Spark UI can allow impersonation if ACLs enabled
High
CVE-2022-33891
was published
for
org.apache.spark:spark-parent_2.12
(Maven)
Jul 19, 2022
Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
High
CVE-2025-54412
was published
for
skops
(pip)
Jul 25, 2025
smolagents has Sandbox Escape Vulnerability in the local_python_executor.py Module
High
CVE-2025-5120
was published
for
smolagents
(pip)
Jul 27, 2025
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
CVE-2025-6998
was published
for
calibreweb
(pip)
Jul 24, 2025
Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
High
CVE-2025-54413
was published
for
skops
(pip)
Jul 25, 2025
FastAPI Guard has a regex bypass
High
CVE-2025-54365
was published
for
fastapi-guard
(pip)
Jul 23, 2025
Cadwyn vulnerable to XSS on the docs page
High
CVE-2025-53528
was published
for
cadwyn
(pip)
Jul 21, 2025
Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory usage
High
CVE-2019-1010083
was published
for
flask
(pip)
Jul 19, 2019
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
High
CVE-2025-54140
was published
for
pyload-ng
(pip)
Jul 21, 2025
Aim vulnerable to Cross-Site Request Forgery
High
CVE-2024-7760
was published
for
aim
(pip)
Mar 20, 2025
Open WebUI Uncontrolled Resource Consumption vulnerability
High
CVE-2024-7036
was published
for
open-webui
(pip)
Mar 20, 2025
LangChain Community SSRF vulnerability exists in RequestsToolkit component
High
CVE-2025-2828
was published
for
langchain-community
(pip)
Jun 23, 2025
aiohttp-session Session Fixation vulnerability
High
CVE-2018-1000519
was published
for
aiohttp-session
(pip)
Sep 13, 2018
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
High
CVE-2025-30402
was published
for
executorch
(pip)
Jul 11, 2025
protobuf susceptible to buffer overflow
High
CVE-2015-5237
was published
for
Google.Protobuf
(Composer)
May 13, 2022
libwebp: OOB write in BuildHuffmanTable
High
CVE-2023-4863
was published
for
Pillow
(Go)
Sep 12, 2023
pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
High
CVE-2025-7346
was published
for
pyload-ng
(pip)
Jul 8, 2025
Duplicate Advisory: GHSA-x698-5hjm-w2m5
High
GHSA-2wcm-vx67-3x4q
was published
for
pyload-ng
(pip)
Jul 8, 2025
•
withdrawn
NULL Pointer Dereference in Protocol Buffers
High
CVE-2021-22570
was published
for
Google.Protobuf
(Composer)
Jan 27, 2022
ProTip!
Advisories are also available from the
GraphQL API