GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,412
Erlang
33
GitHub Actions
22
Go
2,148
Maven
5,000+
npm
3,814
NuGet
689
pip
3,487
Pub
12
RubyGems
901
Rust
900
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,487 advisories
Filter by severity
Duplicate Advisory: Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
GHSA-hw34-rqc5-h2gm
was published
for
picklescan
(pip)
Mar 3, 2025
•
withdrawn
Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
CVE-2025-1716
was published
for
picklescan
(pip)
Mar 3, 2025
PyTorch Model Files Can Bypass Pickle Scanners via Unexpected Pickle Extensions
Moderate
CVE-2025-1889
was published
for
picklescan
(pip)
Mar 3, 2025
CodeChecker open redirect when URL contains multiple slashes after the product name
Moderate
CVE-2025-1300
was published
for
codechecker
(pip)
Mar 3, 2025
Duplicate Advisory: Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
GHSA-vr75-hjh9-7fr6
was published
for
picklescan
(pip)
Mar 3, 2025
•
withdrawn
Flask-AppBuilder Observable Response Discrepancy
Low
CVE-2025-24023
was published
for
flask-appbuilder
(pip)
Mar 3, 2025
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
High
CVE-2025-27154
was published
for
spotipy
(pip)
Feb 28, 2025
copyparty renders unsanitized filenames as HTML when user uploads empty files
Low
CVE-2025-27145
was published
for
copyparty
(pip)
Feb 26, 2025
LTI JupyterHub Authenticator does not properly validate JWT Signature
Critical
CVE-2023-25574
was published
for
jupyterhub-ltiauthenticator
(pip)
Feb 25, 2025
Vyper has a double eval in For List Iter
Low
CVE-2025-27104
was published
for
vyper
(pip)
Feb 21, 2025
AugAssign evaluation order causing OOB write within the object in Vyper
Low
CVE-2025-27105
was published
for
vyper
(pip)
Feb 21, 2025
Vyper's sqrt doesn't define rounding behavior
Low
CVE-2025-26622
was published
for
vyper
(pip)
Feb 21, 2025
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
High
CVE-2025-1403
was published
for
qiskit
(pip)
Feb 21, 2025
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
High
CVE-2025-25305
was published
for
homeassistant
(pip)
Feb 18, 2025
Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0
Moderate
CVE-2025-1057
was published
for
keylime
(pip)
Feb 14, 2025
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
High
CVE-2025-25297
was published
for
label-studio
(pip)
Feb 14, 2025
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
Moderate
CVE-2025-25296
was published
for
label-studio
(pip)
Feb 14, 2025
Label Studio has a Path Traversal Vulnerability via image Field
High
CVE-2025-25295
was published
for
label-studio-sdk
(pip)
Feb 14, 2025
Withdrawn Advisory: Command injection in Ray
Critical
CVE-2024-57000
was published
for
ray
(pip)
Feb 12, 2025
•
withdrawn
Vulnerable OpenSSL included in cryptography wheels
Low
CVE-2024-12797
was published
for
cryptography
(pip)
Feb 11, 2025
PandasAI interactive prompt function Remote Code Execution (RCE)
Critical
CVE-2024-12366
was published
for
pandasai
(pip)
Feb 11, 2025
xml2rfc has file inclusion irregularities
Moderate
GHSA-432c-wxpg-m4q3
was published
for
xml2rfc
(pip)
Feb 7, 2025
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
Low
CVE-2025-25183
was published
for
vllm
(pip)
Feb 6, 2025
Mitmweb API Authentication Bypass Using Proxy Server
High
CVE-2025-23217
was published
for
mitmproxy
(pip)
Feb 6, 2025
ProTip!
Advisories are also available from the
GraphQL API