GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
507 advisories
Filter by severity
Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
Critical
CVE-2025-10157
was published
for
picklescan
(pip)
Sep 10, 2025
Picklescan Bypass is Possible via File Extension Mismatch
Critical
CVE-2025-10155
was published
for
picklescan
(pip)
Sep 10, 2025
Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
Critical
CVE-2025-10156
was published
for
picklescan
(pip)
Sep 10, 2025
Duplicate Advisory: Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
Critical
GHSA-hf6h-9wq7-hmjg
was published
for
picklescan
(pip)
Sep 17, 2025
•
withdrawn
Duplicate Advisory: Picklescan Bypass is Possible via File Extension Mismatch
Critical
GHSA-j424-mc44-f4hj
was published
for
picklescan
(pip)
Sep 17, 2025
•
withdrawn
Duplicate Advisory: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
Critical
GHSA-4vr7-g93g-cf6m
was published
for
picklescan
(pip)
Sep 17, 2025
•
withdrawn
internetarchive Vulnerable to Directory Traversal in File.download()
Critical
CVE-2025-58438
was published
for
internetarchive
(pip)
Sep 5, 2025
DeepDiff Class Pollution in Delta class leading to DoS, Remote Code Execution, and more
Critical
CVE-2025-58367
was published
for
deepdiff
(pip)
Sep 3, 2025
TkEasyGUI Vulnerable to OS Command Injection
Critical
CVE-2025-55037
was published
for
TkEasyGUI
(pip)
Sep 5, 2025
Pixar OpenUSD Sdf_PathNode Module Use-After-Free Vulnerability Leading to Potential Remote Code Execution
Critical
GHSA-58p5-r2f6-g2cj
was published
for
usd-core
(pip)
Sep 4, 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
Critical
CVE-2025-32434
was published
for
torch
(pip)
Apr 18, 2025
ExecuTorch out-of-bounds access vulnerability
Critical
CVE-2025-54950
was published
for
executorch
(pip)
Aug 8, 2025
ExecuTorch vulnerable to Heap-based Buffer Overflow
Critical
CVE-2025-54951
was published
for
executorch
(pip)
Aug 8, 2025
ExecuTorch heap buffer overflow vulnerability
Critical
CVE-2025-54949
was published
for
executorch
(pip)
Aug 8, 2025
ExecuTorch integer overflow vulnerability
Critical
CVE-2025-30405
was published
for
executorch
(pip)
Aug 8, 2025
ExecuTorch integer overflow vulnerability
Critical
CVE-2025-30404
was published
for
executorch
(pip)
Aug 8, 2025
smolagents has Sandbox Escape Vulnerability in the local_python_executor.py Module
Critical
CVE-2025-5120
was published
for
smolagents
(pip)
Jul 27, 2025
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
Critical
CVE-2024-32651
was published
for
changedetection.io
(pip)
Oct 15, 2024
pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
Critical
CVE-2025-54802
was published
for
pyload-ng
(pip)
Aug 4, 2025
num2words subjected to phishing attack, two versions published containing malware
Critical
GHSA-jxr6-qrxx-2ph2
was published
for
num2words
(pip)
Jul 31, 2025
BentoML SSRF Vulnerability in File Upload Processing
Critical
CVE-2025-54381
was published
for
bentoml
(pip)
Jul 29, 2025
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
Critical
CVE-2024-10835
was published
for
dbgpt
(pip)
Mar 20, 2025
pyLoad vulnerable to XSS through insecure CAPTCHA
Critical
CVE-2025-53890
was published
for
pyload-ng
(pip)
Jul 15, 2025
Python Swift client is vulnerable to Missing SSL Certificate Check
Critical
CVE-2013-6396
was published
for
python-swiftclient
(pip)
May 17, 2022
Apache IoTDB Vulnerable to Remote Code Execution
Critical
CVE-2024-24780
was published
for
apache-iotdb
(Maven)
May 14, 2025
ProTip!
Advisories are also available from the
GraphQL API