GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
480 advisories
Filter by severity
AgentScope Deserialization Vulnerability
Critical
CVE-2024-8502
was published
for
agentscope
(pip)
Mar 20, 2025
PyTorch Lightning path traversal vulnerability
Critical
CVE-2024-8019
was published
for
pytorch-lightning
(pip)
Mar 20, 2025
Withdrawn Advisory: PyTorch deserialization vulnerability
Critical
CVE-2024-7804
was published
for
torch
(pip)
Mar 20, 2025
•
withdrawn
Aim External Control of File Name or Path vulnerability
Critical
CVE-2024-6829
was published
for
aim
(pip)
Mar 20, 2025
llama-index-packs-finchat SQL Injection vulnerability
Critical
CVE-2024-12909
was published
for
llama-index-packs-finchat
(pip)
Mar 20, 2025
LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
Critical
CVE-2024-11958
was published
for
llama-index-retrievers-duckdb-retriever
(pip)
Mar 20, 2025
vLLM Deserialization of Untrusted Data vulnerability
Critical
CVE-2024-11041
was published
for
vllm
(pip)
Mar 20, 2025
InvokeAI Arbitrary File Deletion vulnerability
Critical
CVE-2024-11042
was published
for
InvokeAI
(pip)
Mar 20, 2025
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
Critical
CVE-2024-10902
was published
for
dbgpt
(pip)
Mar 20, 2025
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
Critical
CVE-2024-10833
was published
for
dbgpt
(pip)
Mar 20, 2025
DB-GPT Arbitrary File Write vulnerability
Critical
CVE-2024-10901
was published
for
dbgpt
(pip)
Mar 20, 2025
DB-GPT Absolute Path Traversal vulnerability
Critical
CVE-2024-10831
was published
for
dbgpt
(pip)
Mar 20, 2025
H2O Deserialization of Untrusted Data Vulnerability
Critical
CVE-2024-10553
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Withdrawn Advisory: Dask Vulnerable to Command Injection
Critical
CVE-2024-10096
was published
for
dask
(pip)
Mar 20, 2025
•
withdrawn
Horovod Vulnerable to Command Injection
Critical
CVE-2024-10190
was published
for
horovod
(pip)
Mar 20, 2025
vLLM Allows Remote Code Execution via Mooncake Integration
Critical
CVE-2025-29783
was published
for
vllm
(pip)
Mar 19, 2025
Qiskit allows arbitrary code execution decoding QPY format versions < 13
Critical
CVE-2025-2000
was published
for
qiskit
(pip)
Mar 14, 2025
Duplicate Advisory: Qiskit allows arbitrary code execution decoding QPY format versions < 13
Critical
GHSA-3pwp-2fqj-6g2p
was published
for
qiskit
(pip)
Mar 14, 2025
•
withdrawn
LTI JupyterHub Authenticator does not properly validate JWT Signature
Critical
CVE-2023-25574
was published
for
jupyterhub-ltiauthenticator
(pip)
Feb 25, 2025
Withdrawn Advisory: Command injection in Ray
Critical
CVE-2024-57000
was published
for
ray
(pip)
Feb 12, 2025
•
withdrawn
PandasAI interactive prompt function Remote Code Execution (RCE)
Critical
CVE-2024-12366
was published
for
pandasai
(pip)
Feb 11, 2025
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
CVE-2025-24370
was published
for
django-unicorn
(pip)
Feb 3, 2025
Sentry's improper authentication on SAML SSO process allows user impersonation
Critical
CVE-2025-22146
was published
for
sentry
(pip)
Jan 15, 2025
Gradio Blocked Path ACL Bypass Vulnerability
Critical
CVE-2025-23042
was published
for
gradio
(pip)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API