GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,729 advisories
Filter by severity
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
Critical
GHSA-ggpf-24jw-3fcw
was published
for
vllm
(pip)
Apr 23, 2025
OctoPrint Authenticated Reverse Proxy Page Authentication Bypass
Moderate
CVE-2025-32788
was published
for
octoprint
(pip)
Apr 22, 2025
youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization
High
GHSA-22fp-mf44-f2mq
was published
for
youtube-dl
(pip)
Apr 18, 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
Critical
CVE-2025-32434
was published
for
pytorch
(pip)
Apr 18, 2025
Rasa Pro Missing Authentication For Voice Connector APIs
Moderate
CVE-2025-32377
was published
for
rasa-pro
(pip)
Apr 17, 2025
Pycel allows code injection via a crafted formula
High
CVE-2024-53924
was published
for
pycel
(pip)
Apr 17, 2025
PyTorch Improper Resource Shutdown or Release vulnerability
Moderate
CVE-2025-3730
was published
for
torch
(pip)
Apr 16, 2025
Whoogle allows attackers to execute arbitrary code via supplying a crafted search query
High
CVE-2024-53305
was published
for
whoogle-search
(pip)
Apr 16, 2025
vLLM vulnerable to Denial of Service by abusing xgrammar cache
Moderate
GHSA-hf3c-wxg2-49q9
was published
for
vllm
(pip)
Apr 15, 2025
VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext
Low
CVE-2025-32021
was published
for
weblate
(pip)
Apr 15, 2025
TigerVNC accessible via the network and not just via a UNIX socket as intended
Critical
CVE-2025-32428
was published
for
jupyter-remote-desktop-proxy
(pip)
Apr 12, 2025
xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
Moderate
CVE-2025-32381
was published
for
xgrammar
(pip)
Apr 9, 2025
BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-32375
was published
for
bentoml
(pip)
Apr 9, 2025
Picklescan missing detection when calling built-in python library function timeit.timeit()
Moderate
GHSA-v7x6-rv5q-mhwc
was published
for
picklescan
(pip)
Apr 7, 2025
Picklescan failed to detect to some unsafe global function in Numpy library
Moderate
GHSA-fj43-3qmq-673f
was published
for
picklescan
(pip)
Apr 7, 2025
Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
High
CVE-2025-46417
was published
for
picklescan
(pip)
Apr 7, 2025
LNbits Lightning Network Payment System Vulnerable to Server-Side Request Forgery via LNURL Authentication Callback
Critical
CVE-2025-32013
was published
for
lnbits
(pip)
Apr 7, 2025
Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
Critical
CVE-2025-3248
was published
for
langflow
(pip)
Apr 7, 2025
Apache Airflow Common SQL Provider Vulnerable to SQL Injection
High
CVE-2025-30473
was published
for
apache-airflow-providers-common-sql
(pip)
Apr 7, 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-27520
was published
for
bentoml
(pip)
Apr 4, 2025
jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
High
CVE-2025-30370
was published
for
jupyterlab-git
(pip)
Apr 4, 2025
InternLM LMDeploy code injection vulnerability
Moderate
CVE-2025-3163
was published
for
lmdeploy
(pip)
Apr 3, 2025
LMDeploy Improper Input Validation Vulnerability
Moderate
CVE-2025-3162
was published
for
lmdeploy
(pip)
Apr 3, 2025
pgAdmin 4 Vulnerable to Remote Code Execution
Critical
CVE-2025-2945
was published
for
pgadmin4
(pip)
Apr 3, 2025
ProTip!
Advisories are also available from the
GraphQL API