GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,652
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,066 advisories
Filter by severity
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
Moderate
CVE-2025-62707
was published
for
pypdf
(pip)
Oct 22, 2025
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
High
CVE-2025-62611
was published
for
aiomysql
(pip)
Oct 22, 2025
Scapy Session Loading Vulnerable to Arbitrary Code Execution via Untrusted Pickle Deserialization
Moderate
GHSA-cq46-m9x9-j8w2
was published
for
scapy
(pip)
Oct 22, 2025
Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function
Moderate
CVE-2025-11844
was published
for
smolagents
(pip)
Oct 22, 2025
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
Moderate
CVE-2025-62607
was published
for
nautobot-ssot
(pip)
Oct 21, 2025
uv has differential in tar extraction with PAX headers
Low
GHSA-w476-p2h3-79g9
was published
for
uv
(pip)
Oct 21, 2025
Taguette vulnerable to cross-site scripting via tag name, tag description, document name and document description
Moderate
CVE-2025-62528
was published
for
taguette
(pip)
Oct 20, 2025
Taguette password reset link poisoning
High
CVE-2025-62527
was published
for
taguette
(pip)
Oct 20, 2025
Keras framework vulnerable to deserialization of untrusted data
Critical
CVE-2025-49655
was published
for
keras
(pip)
Oct 17, 2025
pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer
Critical
CVE-2025-62515
was published
for
pyquokka
(pip)
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Moderate
CVE-2025-11849
was published
for
Mammoth
(Maven)
Oct 17, 2025
reflex-dev/reflex has an Open Redirect vulnerability
Low
CVE-2025-62379
was published
for
reflex
(pip)
Oct 15, 2025
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
High
CVE-2025-62172
was published
for
homeassistant
(pip)
Oct 14, 2025
llama-index has Insecure Temporary File
High
CVE-2025-7707
was published
for
llama-index
(pip)
Oct 13, 2025
Authlib : JWE zip=DEF decompression bomb enables DoS
Moderate
CVE-2025-62706
was published
for
authlib
(pip)
Oct 10, 2025
python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
Moderate
CVE-2025-61912
was published
for
python-ldap
(pip)
Oct 10, 2025
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
Moderate
CVE-2025-61911
was published
for
python-ldap
(pip)
Oct 10, 2025
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
High
CVE-2025-61920
was published
for
authlib
(pip)
Oct 10, 2025
BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
Critical
CVE-2025-10283
was published
for
bbot
(pip)
Oct 9, 2025
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
Moderate
CVE-2025-10281
was published
for
bbot
(pip)
Oct 9, 2025
BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
Critical
CVE-2025-10284
was published
for
bbot
(pip)
Oct 9, 2025
Python Social Auth - Django has unsafe account association
Moderate
CVE-2025-61783
was published
for
social-auth-app-django
(pip)
Oct 9, 2025
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
scio is vunerable to Remote Command Execution through PyTorch
Critical
GHSA-m9mp-6x32-5rhg
was published
for
scio-pypi
(pip)
Oct 9, 2025
Synapse's invalid device keys degrade federation functionality
Moderate
CVE-2025-61672
was published
for
matrix-synapse
(pip)
Oct 8, 2025
ProTip!
Advisories are also available from the
GraphQL API