GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,486
Maven
5,000+
npm
4,104
NuGet
735
pip
3,918
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
311 advisories
Filter by severity
Weblate has a long session expiry when verifying second factor
Low
CVE-2025-58352
was published
for
Weblate
(pip)
Sep 4, 2025
MobSF Path Traversal in GET /download/<filename> using absolute filenames
Low
CVE-2025-58161
was published
for
mobsf
(pip)
Sep 2, 2025
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Low
CVE-2025-55304
was published
for
Exiv2
(pip)
Aug 29, 2025
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Low
CVE-2025-54080
was published
for
Exiv2
(pip)
Aug 29, 2025
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
Low
CVE-2025-54364
was published
for
knack
(pip)
Aug 20, 2025
•
withdrawn
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
Low
CVE-2025-54363
was published
for
knack
(pip)
Aug 20, 2025
•
withdrawn
Litestar has potential log injection in exception logging
Low
GHSA-674p-xv2x-rf3g
was published
for
litestar
(pip)
Aug 11, 2025
MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
Low
CVE-2025-53011
was published
for
MaterialX
(pip)
Jul 31, 2025
MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return
Low
CVE-2025-53010
was published
for
MaterialX
(pip)
Jul 31, 2025
MS SWIFT Remote Code Execution via unsafe PyYAML deserialization
Low
CVE-2025-50460
was published
for
ms-swift
(pip)
Jul 31, 2025
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
Low
CVE-2025-53643
was published
for
aiohttp
(pip)
Jul 14, 2025
Transformers's Improper Input Validation vulnerability can be exploited through username injection
Low
CVE-2025-3777
was published
for
transformers
(pip)
Jul 7, 2025
pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function
Low
CVE-2025-6518
was published
for
pyspur
(pip)
Jun 23, 2025
Upsonic is vulnerable to Path Traversal attack through its os.path.join function
Low
CVE-2025-6278
was published
for
upsonic
(pip)
Jun 19, 2025
Upsonic has vulnerability in Pickle Handler component that can lead to deserialization
Low
CVE-2025-6279
was published
for
upsonic
(pip)
Jun 19, 2025
Weblate exposes personal IP address via e-mail
Low
CVE-2025-49134
was published
for
weblate
(pip)
Jun 16, 2025
Vantage6 Server JWT secret not cryptographically secure
Low
CVE-2025-43866
was published
for
vantage6-server
(pip)
Jun 12, 2025
vantage6 lacks brute-force protection on change password functionality
Low
CVE-2025-43863
was published
for
vantage6
(pip)
Jun 12, 2025
Gradio CORS Origin Validation Bypass Vulnerability
Low
CVE-2025-5320
was published
for
gradio
(pip)
May 29, 2025
Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
Low
CVE-2025-5321
was published
for
aim
(pip)
May 29, 2025
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
Low
CVE-2025-46570
was published
for
vllm
(pip)
May 28, 2025
Vyper's `slice()` may elide side-effects when output length is 0
Low
CVE-2025-47774
was published
for
vyper
(pip)
May 16, 2025
Vyper's `concat()` builtin may elide side-effects for zero-length arguments
Low
CVE-2025-47285
was published
for
vyper
(pip)
May 16, 2025
Flask uses fallback key instead of current signing key
Low
CVE-2025-47278
was published
for
flask
(pip)
May 13, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
Low
CVE-2025-44021
was published
for
ironic
(pip)
May 8, 2025
ProTip!
Advisories are also available from the
GraphQL API