GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,739 advisories
Filter by severity
Sentry's Python SDK unintentionally exposes environment variables to subprocesses
Low
CVE-2024-40647
was published
for
sentry-sdk
(pip)
Jul 18, 2024
llama_index vulnerable to SQL Injection
Critical
CVE-2025-1793
was published
for
llama-index
(pip)
Jun 5, 2025
Django Improper Output Neutralization for Logs vulnerability
Moderate
CVE-2025-48432
was published
for
Django
(pip)
Jun 5, 2025
HumanSignal label-studio-ml-backend Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-5173
was published
for
label-studio-ml
(pip)
May 26, 2025
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Moderate
CVE-2025-48994
was published
for
signxml
(pip)
Jun 5, 2025
SignXML's signature verification with HMAC is vulnerable to a timing attack
Moderate
CVE-2025-48995
was published
for
signxml
(pip)
Jun 5, 2025
Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
Low
CVE-2025-5321
was published
for
aim
(pip)
May 29, 2025
Gradio CORS Origin Validation Bypass Vulnerability
Low
CVE-2025-5320
was published
for
gradio
(pip)
May 29, 2025
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
High
CVE-2025-48957
was published
for
astrbot
(pip)
Jun 4, 2025
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
High
CVE-2024-45498
was published
for
apache-airflow
(pip)
Sep 7, 2024
pypickle Incorrect Privilege Assignment vulnerability
Moderate
CVE-2025-5175
was published
for
pypickle
(pip)
May 26, 2025
pypickle unsafe deserialization vulnerability
Moderate
CVE-2025-5174
was published
for
pypickle
(pip)
May 26, 2025
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
High
CVE-2025-30167
was published
for
jupyter_core
(pip)
Jun 4, 2025
django-helpdesk Allows Sensitive Data Exposure
Moderate
CVE-2018-25111
was published
for
django-helpdesk
(pip)
May 31, 2025
Apache Superset: Improper authorization bypass on row level security via SQL Injection
High
CVE-2025-48912
was published
for
apache-superset
(pip)
May 30, 2025
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
Moderate
CVE-2025-48944
was published
for
vllm
(pip)
May 28, 2025
vLLM allows clients to crash the openai server with invalid regex
Moderate
CVE-2025-48943
was published
for
vllm
(pip)
May 28, 2025
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
Moderate
CVE-2025-48942
was published
for
vllm
(pip)
May 28, 2025
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
Moderate
CVE-2025-48887
was published
for
vllm
(pip)
May 28, 2025
PyTorch Improper Resource Shutdown or Release vulnerability
Moderate
CVE-2025-3730
was published
for
torch
(pip)
Apr 16, 2025
PyTorch susceptible to local Denial of Service
Low
CVE-2025-2953
was published
for
torch
(pip)
Mar 30, 2025
Unsafe yaml deserialization in llama-hub
Critical
CVE-2024-23730
was published
for
llama-hub
(pip)
Jan 21, 2024
Duplicate Advisory: Bundled libwebp in Pillow vulnerable
High
GHSA-56pw-mpj4-fxww
was published
for
pillow
(pip)
Oct 5, 2023
•
withdrawn
Gradio Allows Unauthorized File Copy via Path Manipulation
Moderate
CVE-2025-48889
was published
for
gradio
(pip)
May 29, 2025
ProTip!
Advisories are also available from the
GraphQL API