GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,679
Erlang
34
GitHub Actions
26
Go
2,268
Maven
5,000+
npm
3,923
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,492 advisories
Filter by severity
LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py
Moderate
CVE-2025-46567
was published
for
llamafactory
(pip)
Apr 23, 2025
Flair allows arbitrary code execution
Moderate
CVE-2024-10073
was published
for
flair
(pip)
Oct 17, 2024
Apache Airflow: DAG Code and Import Error Permissions Ignored
Moderate
CVE-2024-27906
was published
for
apache-airflow
(pip)
Feb 29, 2024
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Moderate
CVE-2025-27516
was published
for
Jinja2
(pip)
Mar 5, 2025
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
Moderate
CVE-2025-46560
was published
for
vllm
(pip)
Apr 29, 2025
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2025-1194
was published
for
transformers
(pip)
Apr 29, 2025
Duplicate Advisory: Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
Moderate
GHSA-4p4h-9gvq-7xfg
was published
for
picklescan
(pip)
Apr 24, 2025
•
withdrawn
LMDeploy Improper Input Validation Vulnerability
Moderate
CVE-2025-3162
was published
for
lmdeploy
(pip)
Apr 3, 2025
InternLM LMDeploy code injection vulnerability
Moderate
CVE-2025-3163
was published
for
lmdeploy
(pip)
Apr 3, 2025
OctoPrint Authenticated Reverse Proxy Page Authentication Bypass
Moderate
CVE-2025-32788
was published
for
octoprint
(pip)
Apr 22, 2025
Rasa Pro Missing Authentication For Voice Connector APIs
Moderate
CVE-2025-32377
was published
for
rasa-pro
(pip)
Apr 17, 2025
Web2py Reflected XSS vulnerability
Moderate
CVE-2016-4807
was published
for
web2py
(pip)
May 17, 2022
PyTorch Improper Resource Shutdown or Release vulnerability
Moderate
CVE-2025-3730
was published
for
torch
(pip)
Apr 16, 2025
vLLM vulnerable to Denial of Service by abusing xgrammar cache
Moderate
GHSA-hf3c-wxg2-49q9
was published
for
vllm
(pip)
Apr 15, 2025
BentoML Open Redirect vulnerability
Moderate
GHSA-564p-rx2q-4c8v
was published
for
bentoml
(pip)
Mar 20, 2025
Pillow Temporary file name leakage
Moderate
CVE-2014-1933
was published
for
Pillow
(pip)
May 18, 2020
OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests
Moderate
CVE-2014-0167
was published
for
nova
(pip)
May 17, 2022
OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
Moderate
CVE-2014-0157
was published
for
horizon
(pip)
May 14, 2022
Roundup Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2012-6130
was published
for
roundup
(pip)
May 17, 2022
OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
Moderate
CVE-2013-2096
was published
for
nova
(pip)
May 17, 2022
cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
Moderate
CVE-2022-42966
was published
for
cleo
(pip)
Nov 10, 2022
Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
CVE-2025-1716
was published
for
picklescan
(pip)
Mar 3, 2025
ProTip!
Advisories are also available from the
GraphQL API