GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,695
Maven
5,000+
npm
4,321
NuGet
761
pip
4,098
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
525 advisories
Filter by severity
Ray's New Token Authentication is Disabled By Default
Critical
CVE-2025-34351
was published
for
ray
(pip)
Nov 27, 2025
Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
Critical
CVE-2025-62593
was published
for
ray
(pip)
Nov 26, 2025
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
Critical
CVE-2025-64459
was published
for
django
(pip)
Nov 5, 2025
Gevent allows remote attacker to escalate privileges
Critical
CVE-2023-41419
was published
for
gevent
(pip)
Sep 25, 2023
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
Critical
CVE-2025-65015
was published
for
joserfc
(pip)
Nov 18, 2025
Modular Max Serve has Unsafe Deserialization vulnerability
Critical
CVE-2025-60455
was published
for
modular
(pip)
Nov 18, 2025
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Critical
CVE-2025-55449
was published
for
astrbot
(pip)
Nov 14, 2025
codechecker authentication method confusion vulnerability allows logging in as the built-in root user from an external service
Critical
CVE-2024-10082
was published
for
codechecker
(pip)
Nov 6, 2024
codechecker vulnerable to authentication bypass when using specifically crafted URLs
Critical
CVE-2024-10081
was published
for
codechecker
(pip)
Nov 6, 2024
pgAdmin4 vulnerable to Remote Code Execution (RCE) when running in server mode
Critical
CVE-2025-12762
was published
for
pgadmin4
(pip)
Nov 13, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
Django SQL injection vulnerability
Critical
CVE-2024-42005
was published
for
Django
(pip)
Aug 7, 2024
GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments
Critical
CVE-2023-40267
was published
for
GitPython
(pip)
Aug 11, 2023
GitPython vulnerable to Remote Code Execution due to improper user input validation
Critical
CVE-2022-24439
was published
for
GitPython
(pip)
Dec 6, 2022
internetarchive Vulnerable to Directory Traversal in File.download()
Critical
CVE-2025-58438
was published
for
internetarchive
(pip)
Sep 5, 2025
Authentication bypass in Apache Airflow
Critical
CVE-2020-13927
was published
for
apache-airflow
(pip)
Apr 30, 2021
SaltStack Salt Command Injection in netapi ssh client
Critical
CVE-2020-16846
was published
for
salt
(pip)
May 24, 2022
pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer
Critical
CVE-2025-62515
was published
for
pyquokka
(pip)
Oct 17, 2025
Withdrawn Advisory: Gradio was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py
Critical
CVE-2024-39236
was published
for
Gradio
(pip)
Jul 1, 2024
•
withdrawn
Keras framework vulnerable to deserialization of untrusted data
Critical
CVE-2025-49655
was published
for
keras
(pip)
Oct 17, 2025
InvokeAI Arbitrary File Deletion vulnerability
Critical
CVE-2024-11042
was published
for
InvokeAI
(pip)
Mar 20, 2025
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
Critical
CVE-2024-10902
was published
for
dbgpt
(pip)
Mar 20, 2025
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
Critical
CVE-2024-10833
was published
for
dbgpt
(pip)
Mar 20, 2025
Horovod Vulnerable to Command Injection
Critical
CVE-2024-10190
was published
for
horovod
(pip)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API