GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,325
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,561 advisories
Filter by severity
mako is vulnerable to Regular Expression Denial of Service
High
CVE-2022-40023
was published
for
mako
(pip)
Sep 16, 2022
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
High
CVE-2025-66416
was published
for
mcp
(pip)
Dec 2, 2025
vLLM vulnerable to remote code execution via transformers_utils/get_config
High
CVE-2025-66448
was published
for
vllm
(pip)
Dec 2, 2025
Keras Directory Traversal Vulnerability
High
CVE-2025-12060
was published
for
keras
(pip)
Dec 2, 2025
Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
GHSA-28jp-44vh-q42h
was published
for
keras
(pip)
Oct 30, 2025
•
withdrawn
trytond does not enforce access rights for the route of the HTML editor.
High
CVE-2025-66423
was published
for
trytond
(pip)
Nov 30, 2025
Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
CVE-2025-12638
was published
for
Keras
(pip)
Nov 28, 2025
•
withdrawn
Apache DolphinScheduler sensitive information disclosure
High
CVE-2023-48796
was published
for
apache-dolphinscheduler
(Maven)
Nov 24, 2023
Cross-Site Request Forgery in sqlite-web
High
CVE-2021-23404
was published
for
sqlite-web
(pip)
Sep 9, 2021
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
High
CVE-2025-64495
was published
for
open-webui
(npm)
Nov 7, 2025
Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
High
CVE-2025-62703
was published
for
fugue
(pip)
Nov 25, 2025
Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devices
High
CVE-2025-13609
was published
for
keylime
(pip)
Nov 24, 2025
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
High
CVE-2025-65106
was published
for
langchain-core
(pip)
Nov 20, 2025
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
High
CVE-2025-62372
was published
for
vllm
(pip)
Nov 20, 2025
vLLM deserialization vulnerability leading to DoS and potential RCE
High
CVE-2025-62164
was published
for
vllm
(pip)
Nov 20, 2025
Arbitrary Code Execution in pdfminer.six via Crafted PDF Input
High
CVE-2025-64512
was published
for
pdfminer.six
(pip)
Nov 7, 2025
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
High
CVE-2025-65073
was published
for
keystone
(pip)
Nov 17, 2025
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
High
CVE-2025-6176
was published
for
Scrapy
(pip)
Oct 31, 2025
Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
High
GHSA-f83h-ghpp-7wcc
was published
for
pdfminer.six
(pip)
Nov 7, 2025
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
CVE-2025-64496
was published
for
open-webui
(npm)
Nov 7, 2025
pgAdmin is affected by an LDAP injection vulnerability
High
CVE-2025-12764
was published
for
pgadmin4
(pip)
Nov 13, 2025
pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification
High
CVE-2025-12765
was published
for
pgadmin4
(pip)
Nov 13, 2025
AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High
CVE-2025-12967
was published
for
aws_advanced_python_wrapper
(pip)
Nov 13, 2025
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
High
CVE-2025-64509
was published
for
bugsink
(pip)
Nov 13, 2025
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input
High
CVE-2025-64508
was published
for
bugsink
(pip)
Nov 13, 2025
ProTip!
Advisories are also available from the
GraphQL API