GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,632
Erlang
34
GitHub Actions
25
Go
2,238
Maven
5,000+
npm
3,900
NuGet
701
pip
3,666
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,666 advisories
Filter by severity
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
GHSA-785h-76cm-cpmf
was published
for
django-tomselect
(pip)
Mar 26, 2025
Frappe has possibility of SQL injection due to improper validations
Moderate
CVE-2025-30217
was published
for
frappe
(pip)
Mar 26, 2025
Frappe vulnerable to information disclosure leading to account takeover
High
CVE-2025-30214
was published
for
frappe
(pip)
Mar 25, 2025
Frappe has Possibility of Remote Code Execution due to improper validation
Moderate
CVE-2025-30213
was published
for
frappe
(pip)
Mar 25, 2025
Frappe has possibility of SQL injection due to improper validations
Moderate
CVE-2025-30212
was published
for
frappe
(pip)
Mar 25, 2025
InvokeAI Deserialization of Untrusted Data vulnerability
Critical
CVE-2024-12029
was published
for
InvokeAI
(pip)
Mar 21, 2025
MLflow Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-1473
was published
for
mlflow
(pip)
Mar 20, 2025
LiteLLM Has a Leakage of Langfuse API Keys
High
CVE-2025-0330
was published
for
litellm
(pip)
Mar 20, 2025
Aim Uncontrolled Resource Consumption vulnerability
High
CVE-2025-0189
was published
for
aim
(pip)
Mar 20, 2025
Aim Excessive Data Query Operations in a Large Data Table vulnerability
High
CVE-2025-0190
was published
for
aim
(pip)
Mar 20, 2025
MLflow Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2025-0453
was published
for
mlflow
(pip)
Mar 20, 2025
LiteLLM Has an Improper Authorization Vulnerability
High
CVE-2025-0628
was published
for
litellm
(pip)
Mar 20, 2025
Duplicate Advisory: D-Tale Command Injection vulnerability
Critical
CVE-2025-0655
was published
for
dtale
(pip)
Mar 20, 2025
•
withdrawn
SageMaker Workflow component allows possibility of MD5 hash collisions
Moderate
CVE-2025-0508
was published
for
sagemaker
(pip)
Mar 20, 2025
Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability
High
GHSA-5ccf-884p-4jjq
was published
for
open-webui
(npm)
Mar 20, 2025
LiteLLM Reveals Portion of API Key via a Logging File
High
CVE-2024-9606
was published
for
litellm
(pip)
Mar 20, 2025
Kedro deserialization vulnerability
Critical
CVE-2024-9701
was published
for
kedro
(pip)
Mar 20, 2025
ZenML unauthenticated DoS via Multipart Boundry
High
CVE-2024-9340
was published
for
zenml
(pip)
Mar 20, 2025
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
Critical
CVE-2024-9052
was published
for
vllm
(pip)
Mar 20, 2025
Quivr unauthenticated Denial of Service (DoS) via Multipart Boundary
High
CVE-2024-9229
was published
for
quivr-core
(pip)
Mar 20, 2025
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
Critical
CVE-2024-9053
was published
for
vllm
(pip)
Mar 20, 2025
BentoML Denial of Service (DoS) via Multipart Boundary
High
CVE-2024-9056
was published
for
bentoml
(pip)
Mar 20, 2025
BentoML deserialization vulnerability
Critical
CVE-2024-9070
was published
for
bentoml
(pip)
Mar 20, 2025
composio Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2024-8952
was published
for
composio-core
(pip)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API