GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,368
Maven
5,000+
npm
3,988
NuGet
720
pip
3,779
Pub
12
RubyGems
926
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,779 advisories
Filter by severity
Pillow vulnerability can cause write buffer overflow on BCn encoding
High
CVE-2025-48379
was published
for
pillow
(pip)
Jul 1, 2025
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
Moderate
CVE-2025-6773
was published
for
lightrag-hku
(pip)
Jun 27, 2025
MobSF vulnerability allows SSRF due to the allow_redirects=True parameter
High
CVE-2024-54000
was published
for
mobsf
(pip)
Jun 27, 2025
LLaMA-Factory allows Code Injection through improper vhead_file safeguards
High
CVE-2025-53002
was published
for
llamafactory
(pip)
Jun 27, 2025
Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperator
Critical
CVE-2025-50213
was published
for
apache-airflow-providers-snowflake
(pip)
Jun 26, 2025
LangChain Community SSRF vulnerability exists in RequestsToolkit component
High
CVE-2025-2828
was published
for
langchain-community
(pip)
Jun 23, 2025
pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function
Low
CVE-2025-6518
was published
for
pyspur
(pip)
Jun 23, 2025
ChangeDetection.io XSS in watch overview
High
CVE-2025-52558
was published
for
changedetection.io
(pip)
Jun 23, 2025
MLFlow SSRF via gateway_proxy_handler
Moderate
CVE-2025-52967
was published
for
mlflow
(pip)
Jun 23, 2025
rfc3161-client has insufficient verification for timestamp response signatures
Critical
CVE-2025-52556
was published
for
rfc3161-client
(pip)
Jun 20, 2025
urllib3 does not control redirects in browsers and Node.js
Moderate
CVE-2025-50182
was published
for
urllib3
(pip)
Jun 18, 2025
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Moderate
CVE-2025-50181
was published
for
urllib3
(pip)
Jun 18, 2025
Mezzanine CMS has a Stored Cross-Site Scripting (XSS) vulnerability in the displayable_links_js function
Moderate
CVE-2025-6050
was published
for
Mezzanine
(pip)
Jun 17, 2025
python-a2a has a path traversal in the create_workflow function
Moderate
CVE-2025-6167
was published
for
python-a2a
(pip)
Jun 17, 2025
pycares has a Use-After-Free Vulnerability
Moderate
GHSA-5qpg-rh4j-qp35
was published
for
pycares
(pip)
Jun 16, 2025
protobuf-python has a potential Denial of Service issue
High
CVE-2025-4565
was published
for
protobuf
(pip)
Jun 16, 2025
Weblate exposes personal IP address via e-mail
Low
CVE-2025-49134
was published
for
weblate
(pip)
Jun 16, 2025
Weblate lacks rate limiting when verifying second factor
Moderate
CVE-2025-47951
was published
for
weblate
(pip)
Jun 16, 2025
Salt's worker process vulnerable to denial of service through file read operation
Moderate
CVE-2025-22242
was published
for
salt
(pip)
Jun 13, 2025
Salt vulnerable to directory traversal attack in file receiving method
Critical
CVE-2024-38824
was published
for
salt
(pip)
Jun 13, 2025
Salt vulnerable to arbitrary event injection
High
CVE-2025-22239
was published
for
salt
(pip)
Jun 13, 2025
Salt vulnerable to directory traversal attack in minion file cache creation
Moderate
CVE-2025-22238
was published
for
salt
(pip)
Jun 13, 2025
Salt has minion event bus authorization bypass vulnerability
High
CVE-2025-22236
was published
for
salt
(pip)
Jun 13, 2025
Salt's on demand pillar functionality vulnerable to arbitrary command injections
Moderate
CVE-2025-22237
was published
for
salt
(pip)
Jun 13, 2025
ProTip!
Advisories are also available from the
GraphQL API