GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            518 advisories
        Filter by severity
        
      
      
    
                    
                      Authentication bypass in Apache Airflow
                    
                      
  Critical
                    
                
                      
                        CVE-2020-13927
                      
                      was published
                        for
                        
                          apache-airflow
                        
                        (pip)
                      Apr 30, 2021 
                    
                  
                    
                      SaltStack Salt Command Injection in netapi ssh client
                    
                      
  Critical
                    
                
                      
                        CVE-2020-16846
                      
                      was published
                        for
                        
                          salt
                        
                        (pip)
                      May 24, 2022 
                    
                  
                    
                      pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62515
                      
                      was published
                        for
                        
                          pyquokka
                        
                        (pip)
                      Oct 17, 2025 
                    
                  
                    
                      Withdrawn Advisory: Gradio was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py
                    
                      
  Critical
                    
                
                      
                        CVE-2024-39236
                      
                      was published
                        for
                        
                          Gradio
                        
                        (pip)
                      Jul 1, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      Keras framework vulnerable to deserialization of untrusted data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-49655
                      
                      was published
                        for
                        
                          keras
                        
                        (pip)
                      Oct 17, 2025 
                    
                  
                    
                      InvokeAI Arbitrary File Deletion vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2024-11042
                      
                      was published
                        for
                        
                          InvokeAI
                        
                        (pip)
                      Mar 20, 2025 
                    
                  
                    
                      DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
                    
                      
  Critical
                    
                
                      
                        CVE-2024-10902
                      
                      was published
                        for
                        
                          dbgpt
                        
                        (pip)
                      Mar 20, 2025 
                    
                  
                    
                      DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
                    
                      
  Critical
                    
                
                      
                        CVE-2024-10833
                      
                      was published
                        for
                        
                          dbgpt
                        
                        (pip)
                      Mar 20, 2025 
                    
                  
                    
                      Horovod Vulnerable to Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2024-10190
                      
                      was published
                        for
                        
                          horovod
                        
                        (pip)
                      Mar 20, 2025 
                    
                  
                    
                      pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
                    
                      
  Critical
                    
                
                      
                        CVE-2024-5980
                      
                      was published
                        for
                        
                          lightning
                        
                        (pip)
                      Jun 27, 2024 
                    
                  
                    
                      qdrant input validation failure 
                    
                      
  Critical
                    
                
                      
                        CVE-2024-3829
                      
                      was published
                        for
                        
                          qdrant-client
                        
                        (pip)
                      Jun 3, 2024 
                    
                  
                    
                      BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10283
                      
                      was published
                        for
                        
                          bbot
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10284
                      
                      was published
                        for
                        
                          bbot
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      scio is vunerable to  Remote Command Execution  through PyTorch
                    
                      
  Critical
                    
                
                      
                        GHSA-m9mp-6x32-5rhg
                      
                      was published
                        for
                        
                          scio-pypi
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      ExecuTorch integer overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-30405
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch integer overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-30404
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch vulnerable to Heap-based Buffer Overflow
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54951
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch heap buffer overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54949
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch out-of-bounds access vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54950
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      Apache Pyfory python is vulnerable to deserialization of untrusted data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61622
                      
                      was published
                        for
                        
                          pyfory
                        
                        (pip)
                      Oct 1, 2025 
                    
                  
                    
                      Ray has arbitrary code execution via jobs submission API
                    
                      
  Critical
                    
                
                      
                        CVE-2023-48022
                      
                      was published
                        for
                        
                          ray
                        
                        (pip)
                      Nov 28, 2023 
                    
                  
                    
                      mcp-kubernetes-server has an OS Command Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59377
                      
                      was published
                        for
                        
                          mcp-kubernetes-server
                        
                        (pip)
                      Sep 15, 2025 
                    
                  
                    
                      InvokeAI has External Control of File Name or Path
                    
                      
  Critical
                    
                
                      
                        CVE-2025-6237
                      
                      was published
                        for
                        
                          invokeai
                        
                        (pip)
                      Sep 18, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API