GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,033
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            322 advisories
        Filter by severity
        
      
      
    
                    
                      Byaidu PDFMathTranslate vulnerable to open redirect
                    
                      
  Low
                    
                
                      
                        CVE-2025-50736
                      
                      was published
                        for
                        
                          pdf2zh
                        
                        (pip)
                      Oct 30, 2025 
                    
                  
                    
                      DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
                    
                      
  Low
                    
                
                      
                        CVE-2025-61677
                      
                      was published
                        for
                        
                          datachain
                        
                        (pip)
                      Oct 2, 2025 
                    
                  
                    
                      uv has differential in tar extraction with PAX headers
                    
                      
  Low
                    
                
                      
                        GHSA-w476-p2h3-79g9
                      
                      was published
                        for
                        
                          uv
                        
                        (pip)
                      Oct 21, 2025 
                    
                  
                    
                      reflex-dev/reflex has an Open Redirect vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-62379
                      
                      was published
                        for
                        
                          reflex
                        
                        (pip)
                      Oct 15, 2025 
                    
                  
                    
                      Django vulnerable to partial directory traversal via archives
                    
                      
  Low
                    
                
                      
                        CVE-2025-59682
                      
                      was published
                        for
                        
                          django
                        
                        (pip)
                      Oct 1, 2025 
                    
                  
                    
                      JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
                    
                      
  Low
                    
                
                      
                        CVE-2025-59842
                      
                      was published
                        for
                        
                          jupyterlab
                        
                        (pip)
                      Sep 26, 2025 
                    
                  
                    
                      ml-logger deserialization vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-10950
                      
                      was published
                        for
                        
                          ml-logger
                        
                        (pip)
                      Sep 25, 2025 
                    
                  
                    
                      Langchain-Chatchat has a Path Traversal vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-6853
                      
                      was published
                        for
                        
                          langchain-chatchat
                        
                        (pip)
                      Jun 29, 2025 
                    
                  
                    
                      WebSSH Cross-site Scripting vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-7885
                      
                      was published
                        for
                        
                          webssh
                        
                        (pip)
                      Jul 20, 2025 
                    
                  
                    
                      Fides has a Lack of Brute-Force Protections on Authentication Endpoints
                    
                      
  Low
                    
                
                      
                        CVE-2025-57815
                      
                      was published
                        for
                        
                          ethyca-fides
                        
                        (pip)
                      Sep 8, 2025 
                    
                  
                    
                      Fides' Admin UI User Password Change Does Not Invalidate Current Session
                    
                      
  Low
                    
                
                      
                        CVE-2025-57766
                      
                      was published
                        for
                        
                          ethyca-fides
                        
                        (pip)
                      Sep 8, 2025 
                    
                  
                    
                      Weblate has a long session expiry when verifying second factor
                    
                      
  Low
                    
                
                      
                        CVE-2025-58352
                      
                      was published
                        for
                        
                          Weblate
                        
                        (pip)
                      Sep 4, 2025 
                    
                  
                    
                      MobSF Path Traversal in GET /download/<filename> using absolute filenames
                    
                      
  Low
                    
                
                      
                        CVE-2025-58161
                      
                      was published
                        for
                        
                          mobsf
                        
                        (pip)
                      Sep 2, 2025 
                    
                  
                    
                      Improper Privilege Management in djangorestframework-simplejwt
                    
                      
  Low
                    
                
                      
                        CVE-2024-22513
                      
                      was published
                        for
                        
                          djangorestframework-simplejwt
                        
                        (pip)
                      Mar 16, 2024 
                    
                  
                    
                      Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
                    
                      
  Low
                    
                
                      
                        CVE-2025-55304
                      
                      was published
                        for
                        
                          Exiv2
                        
                        (pip)
                      Aug 29, 2025 
                    
                  
                    
                      Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
                    
                      
  Low
                    
                
                      
                        CVE-2025-54080
                      
                      was published
                        for
                        
                          Exiv2
                        
                        (pip)
                      Aug 29, 2025 
                    
                  
                    
                      Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
                    
                      
  Low
                    
                
                      
                        CVE-2025-54364
                      
                      was published
                        for
                        
                          knack
                        
                        (pip)
                      Aug 20, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
                    
                      
  Low
                    
                
                      
                        CVE-2025-54363
                      
                      was published
                        for
                        
                          knack
                        
                        (pip)
                      Aug 20, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Litestar has potential log injection in exception logging
                    
                      
  Low
                    
                
                      
                        GHSA-674p-xv2x-rf3g
                      
                      was published
                        for
                        
                          litestar
                        
                        (pip)
                      Aug 11, 2025 
                    
                  
                    
                      MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
                    
                      
  Low
                    
                
                      
                        CVE-2025-53011
                      
                      was published
                        for
                        
                          MaterialX
                        
                        (pip)
                      Jul 31, 2025 
                    
                  
                    
                      MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return
                    
                      
  Low
                    
                
                      
                        CVE-2025-53010
                      
                      was published
                        for
                        
                          MaterialX
                        
                        (pip)
                      Jul 31, 2025 
                    
                  
                    
                      MS SWIFT Remote Code Execution via unsafe PyYAML deserialization
                    
                      
  Low
                    
                
                      
                        CVE-2025-50460
                      
                      was published
                        for
                        
                          ms-swift
                        
                        (pip)
                      Jul 31, 2025 
                    
                  
                    
                      Weblate exposes personal IP address via e-mail
                    
                      
  Low
                    
                
                      
                        CVE-2025-49134
                      
                      was published
                        for
                        
                          weblate
                        
                        (pip)
                      Jun 16, 2025 
                    
                  
                    
                      Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
                    
                      
  Low
                    
                
                      
                        CVE-2024-53947
                      
                      was published
                        for
                        
                          apache-superset
                        
                        (pip)
                      Dec 9, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API