GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,153
Maven
5,000+
npm
3,818
NuGet
693
pip
3,492
Pub
12
RubyGems
902
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,348 advisories
Filter by severity
Flask-AppBuilder Has No Rate Limiting on Login AUTH DB
High
CVE-2023-29005
was published
for
Flask-AppBuilder
(pip)
Apr 10, 2023
Improper Authentication in Flask-AppBuilder
High
CVE-2021-41265
was published
for
Flask-AppBuilder
(pip)
Dec 9, 2021
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
High
CVE-2025-25362
was published
for
spacy-llm
(pip)
Mar 5, 2025
dmlc/dgl Vulnerable to Remote Code Execution by Pickle Deserialization via rpc.recv_request()
High
GHSA-3x5x-fw77-g54c
was published
for
dgl
(pip)
Mar 5, 2025
OctoPrint has an Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled
High
CVE-2024-32977
was published
for
OctoPrint
(pip)
May 14, 2024
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
High
CVE-2025-27154
was published
for
spotipy
(pip)
Feb 28, 2025
MobSF Stored Cross-Site Scripting (XSS)
High
CVE-2025-24803
was published
for
mobsf
(pip)
Feb 5, 2025
Ansible vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2024-8775
was published
for
ansible-core
(pip)
Sep 16, 2024
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
High
CVE-2025-1403
was published
for
qiskit
(pip)
Feb 21, 2025
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
High
CVE-2024-34069
was published
for
Werkzeug
(pip)
May 6, 2024
uniapi version 1.0.7 contained an information harvesting script.
High
GHSA-gvvw-rr8m-fj76
was published
for
uniapi
(pip)
Jan 27, 2025
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
High
CVE-2025-25305
was published
for
homeassistant
(pip)
Feb 18, 2025
LightGBM Remote Code Execution Vulnerability
High
CVE-2024-43598
was published
for
lightgbm
(pip)
Nov 12, 2024
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
High
CVE-2025-25297
was published
for
label-studio
(pip)
Feb 14, 2025
Label Studio has a Path Traversal Vulnerability via image Field
High
CVE-2025-25295
was published
for
label-studio-sdk
(pip)
Feb 14, 2025
Deserialization of Untrusted Data in Hugging Face Transformers
High
CVE-2024-11393
was published
for
transformers
(pip)
Nov 23, 2024
Deserialization of Untrusted Data in Hugging Face Transformers
High
CVE-2024-11392
was published
for
transformers
(pip)
Nov 23, 2024
Deserialization of Untrusted Data in Hugging Face Transformers
High
CVE-2024-11394
was published
for
transformers
(pip)
Nov 23, 2024
Apache Airflow: pickle deserialization vulnerability in XComs
High
CVE-2023-50943
was published
for
apache-airflow
(pip)
Jan 24, 2024
Apache Airflow: Bypass permission verification to read code of other dags
High
CVE-2023-50944
was published
for
apache-airflow
(pip)
Jan 24, 2024
Remote Code Execution vulnerability in Apache IoTDB via UDF
High
CVE-2023-46226
was published
for
apache-iotdb
(Maven)
Jan 15, 2024
Apache Superset incorrect write permissions vulnerability
High
CVE-2023-49734
was published
for
apache-superset
(pip)
Dec 19, 2023
ProTip!
Advisories are also available from the
GraphQL API