GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            518 advisories
        Filter by severity
        
      
      
    
                    
                      Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
                    
                      
  Critical
                    
                
                      
                        GHSA-83fm-w79m-64r5
                      
                      was published
                        for
                        
                          mlflow
                        
                        (pip)
                      May 1, 2023 
                    
                  
                    
                      Buffer overflow in sponge queue functions
                    
                      
  Critical
                    
                
                      
                        CVE-2022-37454
                      
                      was published
                        for
                        
                          pysha3
                        
                        (RubyGems)
                      Apr 26, 2023 
                    
                  
                    
                      Radicale is vulnerable to directory traversal on Windows Filesystem Storage Backend component
                    
                      
  Critical
                    
                
                      
                        CVE-2016-1505
                      
                      was published
                        for
                        
                          Radicale
                        
                        (pip)
                      May 17, 2022 
                    
                  
                    
                      web2py remote code execution via hardcoded encryption key in session.connect function
                    
                      
  Critical
                    
                
                      
                        CVE-2016-3953
                      
                      was published
                        for
                        
                          web2py
                        
                        (pip)
                      May 14, 2022 
                    
                  
                    
                      web2py is vulnerable to password brute-force attack
                    
                      
  Critical
                    
                
                      
                        CVE-2016-10321
                      
                      was published
                        for
                        
                          web2py
                        
                        (pip)
                      May 14, 2022 
                    
                  
                    
                      Duplicate Advisory: Improper Restriction of XML External Entity Reference in pikepdf
                    
                      
  Critical
                    
                
                      
                        CVE-2021-46849
                      
                      was published
                        for
                        
                          pikepdf
                        
                        (pip)
                      Oct 24, 2022 
                        •
                        
                          withdrawn
                    
                  
                    
                      Shinken Solutions Shinken Monitoring vulnerable to Incorrect Access Control
                    
                      
  Critical
                    
                
                      
                        CVE-2022-37298
                      
                      was published
                        for
                        
                          Shinken
                        
                        (pip)
                      Oct 20, 2022 
                    
                  
                    
                      Duplicate Advisory: Incorrect Authorization in Gerapy
                    
                      
  Critical
                    
                
                      
                        CVE-2021-44597
                      
                      was published
                        for
                        
                          gerapy
                        
                        (pip)
                      Mar 11, 2022 
                        •
                        
                          withdrawn
                    
                  
                    
                      calibre-web is vulnerable to Business Logic Errors
                    
                      
  Critical
                    
                
                      
                        CVE-2021-4171
                      
                      was published
                        for
                        
                          calibreweb
                        
                        (pip)
                      Jan 21, 2022 
                    
                  
                    
                      Server-Side Request Forgery in calibreweb
                    
                      
  Critical
                    
                
                      
                        CVE-2022-0767
                      
                      was published
                        for
                        
                          calibreweb
                        
                        (pip)
                      Mar 8, 2022 
                    
                  
                    
                      Server-Side Request Forgery in calibreweb
                    
                      
  Critical
                    
                
                      
                        CVE-2022-0766
                      
                      was published
                        for
                        
                          calibreweb
                        
                        (pip)
                      Mar 8, 2022 
                    
                  
                    
                      SQL injection in apache-superset
                    
                      
  Critical
                    
                
                      
                        CVE-2022-27479
                      
                      was published
                        for
                        
                          apache-superset
                        
                        (pip)
                      Apr 14, 2022 
                    
                  
                    
                      NVFLARE unsafe deserialization due to Pickle
                    
                      
  Critical
                    
                
                      
                        CVE-2022-34668
                      
                      was published
                        for
                        
                          nvflare
                        
                        (pip)
                      Aug 31, 2022 
                    
                  
                    
                      SatyaLab opendiamond 10.1.1 vulnerable to path traversal because Flask send_file function used unsafely
                    
                      
  Critical
                    
                
                      
                        CVE-2022-31506
                      
                      was published
                        for
                        
                          opendiamond
                        
                        (pip)
                      Jul 12, 2022 
                    
                  
                    
                      Unsafe yaml deserialization in NVFlare
                    
                      
  Critical
                    
                
                      
                        CVE-2022-31605
                      
                      was published
                        for
                        
                          nvflare
                        
                        (pip)
                      Jun 22, 2022 
                    
                  
                    
                      Unsafe deserialisation in the PKI implementation scheme of NVFlare
                    
                      
  Critical
                    
                
                      
                        CVE-2022-31604
                      
                      was published
                        for
                        
                          nvflare
                        
                        (pip)
                      Jun 22, 2022 
                    
                  
                    
                      fief-server Server-Side Template Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        GHSA-hj8m-9fhf-v7jp
                      
                      was published
                        for
                        
                          fief-server
                        
                        (pip)
                      Jun 23, 2023 
                    
                  
                    
                      HTTP Request Smuggling: Content-Length Sent Twice in Waitress
                    
                      
  Critical
                    
                
                      
                        GHSA-4ppp-gpcr-7qf6
                      
                      was published
                        for
                        
                          waitress
                        
                        (pip)
                      Dec 20, 2019 
                    
                  
                    
                      HTTP/2 DoS Attacks: Ping, Reset, and Settings Floods
                    
                      
  Critical
                    
                
                      
                        GHSA-32gv-6cf3-wcmq
                      
                      was published
                        for
                        
                          twisted
                        
                        (pip)
                      Mar 14, 2022 
                    
                  
                    
                      Use of Externally-Controlled Format String in consoleme
                    
                      
  Critical
                    
                
                      
                        CVE-2022-27177
                      
                      was published
                        for
                        
                          consoleme
                        
                        (pip)
                      Apr 3, 2022 
                    
                  
                    
                      Improper Neutralization of Argument Delimiters in a Decompiling Package Process in APKLeaks
                    
                      
  Critical
                    
                
                      
                        CVE-2021-21386
                      
                      was published
                        for
                        
                          APKLeaks
                        
                        (pip)
                      Jan 21, 2022 
                    
                  
                    
                      Implementation trusts the "me" field returned by the authorization server without verifying it
                    
                      
  Critical
                    
                
                      
                        GHSA-mjcr-rqjg-rhg3
                      
                      was published
                        for
                        
                          datasette-indieauth
                        
                        (pip)
                      Nov 24, 2020 
                    
                  
                    
                      TorchServe Pre-Auth Remote Code Execution
                    
                      
  Critical
                    
                
                      
                        GHSA-4mqg-h5jf-j9m7
                      
                      was published
                        for
                        
                          torchserve
                        
                        (pip)
                      Oct 2, 2023 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API