GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,383
Erlang
33
GitHub Actions
22
Go
2,141
Maven
5,000+
npm
3,803
NuGet
687
pip
3,479
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,479 advisories
Filter by severity
LTI JupyterHub Authenticator does not properly validate JWT Signature
Critical
CVE-2023-25574
was published
for
jupyterhub-ltiauthenticator
(pip)
Feb 25, 2025
langchain_experimental vulnerable to arbitrary code execution via PALChain in the python exec method
Critical
CVE-2023-44467
was published
for
langchain-experimental
(pip)
Oct 9, 2023
Vyper has a double eval in For List Iter
Low
CVE-2025-27104
was published
for
vyper
(pip)
Feb 21, 2025
AugAssign evaluation order causing OOB write within the object in Vyper
Low
CVE-2025-27105
was published
for
vyper
(pip)
Feb 21, 2025
Vyper's sqrt doesn't define rounding behavior
Low
CVE-2025-26622
was published
for
vyper
(pip)
Feb 21, 2025
Ansible vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2024-8775
was published
for
ansible-core
(pip)
Sep 16, 2024
Jupyter Server Proxy's Websocket Proxying does not require authentication
Critical
CVE-2024-28179
was published
for
jupyter-server-proxy
(pip)
Mar 20, 2024
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
High
CVE-2025-1403
was published
for
qiskit
(pip)
Feb 21, 2025
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
High
CVE-2024-34069
was published
for
Werkzeug
(pip)
May 6, 2024
Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library
Critical
CVE-2023-39631
was published
for
langchain
(pip)
Sep 1, 2023
uniapi version 1.0.7 contained an information harvesting script.
High
GHSA-gvvw-rr8m-fj76
was published
for
uniapi
(pip)
Jan 27, 2025
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
High
CVE-2025-25305
was published
for
homeassistant
(pip)
Feb 18, 2025
python-jose algorithm confusion with OpenSSH ECDSA keys
Critical
CVE-2024-33663
was published
for
python-jose
(pip)
Apr 26, 2024
python-jose denial of service via compressed JWE content
Moderate
CVE-2024-33664
was published
for
python-jose
(pip)
Apr 26, 2024
LightGBM Remote Code Execution Vulnerability
High
CVE-2024-43598
was published
for
lightgbm
(pip)
Nov 12, 2024
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
Moderate
CVE-2025-25296
was published
for
label-studio
(pip)
Feb 14, 2025
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
High
CVE-2025-25297
was published
for
label-studio
(pip)
Feb 14, 2025
Withdrawn Advisory: Command injection in Ray
Critical
CVE-2024-57000
was published
for
ray
(pip)
Feb 12, 2025
•
withdrawn
Label Studio has a Path Traversal Vulnerability via image Field
High
CVE-2025-25295
was published
for
label-studio-sdk
(pip)
Feb 14, 2025
Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0
Moderate
CVE-2025-1057
was published
for
keylime
(pip)
Feb 14, 2025
Deserialization of Untrusted Data in Hugging Face Transformers
High
CVE-2024-11393
was published
for
transformers
(pip)
Nov 23, 2024
Deserialization of Untrusted Data in Hugging Face Transformers
High
CVE-2024-11392
was published
for
transformers
(pip)
Nov 23, 2024
Deserialization of Untrusted Data in Hugging Face Transformers
High
CVE-2024-11394
was published
for
transformers
(pip)
Nov 23, 2024
ProTip!
Advisories are also available from the
GraphQL API