GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,815
Erlang
36
GitHub Actions
32
Go
2,401
Maven
5,000+
npm
4,045
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
304 advisories
Filter by severity
MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
Low
CVE-2025-53011
was published
for
MaterialX
(pip)
Jul 31, 2025
MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return
Low
CVE-2025-53010
was published
for
MaterialX
(pip)
Jul 31, 2025
MS SWIFT Remote Code Execution via unsafe PyYAML deserialization
Low
CVE-2025-50460
was published
for
ms-swift
(pip)
Jul 31, 2025
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
Low
CVE-2025-53643
was published
for
aiohttp
(pip)
Jul 14, 2025
Transformers's Improper Input Validation vulnerability can be exploited through username injection
Low
CVE-2025-3777
was published
for
transformers
(pip)
Jul 7, 2025
pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function
Low
CVE-2025-6518
was published
for
pyspur
(pip)
Jun 23, 2025
Upsonic has vulnerability in Pickle Handler component that can lead to deserialization
Low
CVE-2025-6279
was published
for
upsonic
(pip)
Jun 19, 2025
Upsonic is vulnerable to Path Traversal attack through its os.path.join function
Low
CVE-2025-6278
was published
for
upsonic
(pip)
Jun 19, 2025
Weblate exposes personal IP address via e-mail
Low
CVE-2025-49134
was published
for
weblate
(pip)
Jun 16, 2025
Vantage6 Server JWT secret not cryptographically secure
Low
CVE-2025-43866
was published
for
vantage6-server
(pip)
Jun 12, 2025
vantage6 lacks brute-force protection on change password functionality
Low
CVE-2025-43863
was published
for
vantage6
(pip)
Jun 12, 2025
Gradio CORS Origin Validation Bypass Vulnerability
Low
CVE-2025-5320
was published
for
gradio
(pip)
May 29, 2025
Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
Low
CVE-2025-5321
was published
for
aim
(pip)
May 29, 2025
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
Low
CVE-2025-46570
was published
for
vllm
(pip)
May 28, 2025
Vyper's `slice()` may elide side-effects when output length is 0
Low
CVE-2025-47774
was published
for
vyper
(pip)
May 16, 2025
Vyper's `concat()` builtin may elide side-effects for zero-length arguments
Low
CVE-2025-47285
was published
for
vyper
(pip)
May 16, 2025
Flask uses fallback key instead of current signing key
Low
CVE-2025-47278
was published
for
flask
(pip)
May 13, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
Low
CVE-2025-44021
was published
for
ironic
(pip)
May 8, 2025
AWorld OS Command Injection vulnerability
Low
CVE-2025-4032
was published
for
aworld
(pip)
Apr 28, 2025
markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption
Low
CVE-2025-46656
was published
for
markdownify
(pip)
Apr 27, 2025
VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext
Low
CVE-2025-32021
was published
for
weblate
(pip)
Apr 15, 2025
PyTorch susceptible to local Denial of Service
Low
CVE-2025-2953
was published
for
torch
(pip)
Mar 30, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
GHSA-785h-76cm-cpmf
was published
for
django-tomselect
(pip)
Mar 26, 2025
Flask-AppBuilder Observable Response Discrepancy
Low
CVE-2025-24023
was published
for
flask-appbuilder
(pip)
Mar 3, 2025
ProTip!
Advisories are also available from the
GraphQL API