GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,683 advisories
Filter by severity
OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability
Moderate
GHSA-grjp-54v3-c442
was published
for
usd-core
(pip)
Oct 29, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
GHSA-pqhf-p39g-3x64
was published
for
uv
(pip)
Oct 29, 2025
CKAN vulnerable to fixed session IDs
Moderate
CVE-2025-64100
was published
for
ckan
(pip)
Oct 29, 2025
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
Moderate
CVE-2025-62801
was published
for
fastmcp
(pip)
Oct 29, 2025
FastMCP vulnerable to reflected XSS in client's callback page
Moderate
CVE-2025-62800
was published
for
fastmcp
(pip)
Oct 29, 2025
CKAN vulnerable to stored XSS in resource description
Moderate
CVE-2025-54384
was published
for
ckan
(pip)
Oct 29, 2025
Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
Moderate
CVE-2025-12058
was published
for
keras
(pip)
Oct 29, 2025
BBOT's gitlab.py exposes globally configured "gitlab" API key
Moderate
CVE-2025-10282
was published
for
bbot
(pip)
Oct 27, 2025
pypdf can exhaust RAM via manipulated LZWDecode streams
Moderate
CVE-2025-62708
was published
for
pypdf
(pip)
Oct 22, 2025
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
Moderate
CVE-2025-62707
was published
for
pypdf
(pip)
Oct 22, 2025
Scapy Session Loading Vulnerable to Arbitrary Code Execution via Untrusted Pickle Deserialization
Moderate
GHSA-cq46-m9x9-j8w2
was published
for
scapy
(pip)
Oct 22, 2025
Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function
Moderate
CVE-2025-11844
was published
for
smolagents
(pip)
Oct 22, 2025
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
Moderate
CVE-2025-62607
was published
for
nautobot-ssot
(pip)
Oct 21, 2025
Taguette vulnerable to cross-site scripting via tag name, tag description, document name and document description
Moderate
CVE-2025-62528
was published
for
taguette
(pip)
Oct 20, 2025
Mammoth is vulnerable to Directory Traversal
Moderate
CVE-2025-11849
was published
for
Mammoth
(Maven)
Oct 17, 2025
Authlib : JWE zip=DEF decompression bomb enables DoS
Moderate
CVE-2025-62706
was published
for
authlib
(pip)
Oct 10, 2025
python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
Moderate
CVE-2025-61912
was published
for
python-ldap
(pip)
Oct 10, 2025
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
Moderate
CVE-2025-61911
was published
for
python-ldap
(pip)
Oct 10, 2025
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
Moderate
CVE-2025-10281
was published
for
bbot
(pip)
Oct 9, 2025
Python Social Auth - Django has unsafe account association
Moderate
CVE-2025-61783
was published
for
social-auth-app-django
(pip)
Oct 9, 2025
Synapse's invalid device keys degrade federation functionality
Moderate
CVE-2025-61672
was published
for
matrix-synapse
(pip)
Oct 8, 2025
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
Moderate
CVE-2025-61620
was published
for
vllm
(pip)
Oct 7, 2025
python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments
Moderate
CVE-2025-61765
was published
for
python-socketio
(pip)
Oct 7, 2025
clearml is vulnerable to Path Traversal through its `safe_extract` function
Moderate
CVE-2025-8917
was published
for
clearml
(pip)
Oct 5, 2025
ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
Moderate
CVE-2025-8406
was published
for
zenml
(pip)
Oct 5, 2025
ProTip!
Advisories are also available from the
GraphQL API