GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,688
Erlang
34
GitHub Actions
26
Go
2,274
Maven
5,000+
npm
3,930
NuGet
706
pip
3,696
Pub
12
RubyGems
919
Rust
955
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,696 advisories
Filter by severity
OpenStack Ironic fails to restrict paths used for file:// image URLs
Low
CVE-2025-44021
was published
for
ironic
(pip)
May 8, 2025
Django has a denial-of-service possibility in strip_tags()
Moderate
CVE-2025-32873
was published
for
Django
(pip)
May 8, 2025
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
High
CVE-2025-30165
was published
for
vllm
(pip)
May 6, 2025
Mezzanine CMS Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-29573
was published
for
Mezzanine
(pip)
May 5, 2025
Langroid Allows XXE Injection via XMLToolMessage
High
CVE-2025-46726
was published
for
langroid
(pip)
May 5, 2025
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
Moderate
CVE-2025-46730
was published
for
mobsf
(pip)
May 5, 2025
Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL
Critical
CVE-2025-47241
was published
for
browser-use
(pip)
May 5, 2025
Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
Moderate
CVE-2025-46335
was published
for
mobsf
(pip)
May 5, 2025
Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URL
Critical
GHSA-f54f-hr32-586f
was published
for
browser-use
(pip)
May 3, 2025
•
withdrawn
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
Moderate
CVE-2025-46560
was published
for
vllm
(pip)
Apr 29, 2025
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
Critical
CVE-2025-32444
was published
for
vllm
(pip)
Apr 29, 2025
Data exposure via ZeroMQ on multi-node vLLM deployment
High
CVE-2025-30202
was published
for
vllm
(pip)
Apr 29, 2025
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2025-1194
was published
for
transformers
(pip)
Apr 29, 2025
AWorld OS Command Injection vulnerability
Low
CVE-2025-4032
was published
for
aworld
(pip)
Apr 28, 2025
markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption
Low
CVE-2025-46656
was published
for
markdownify
(pip)
Apr 27, 2025
h11 accepts some malformed Chunked-Encoding bodies
Critical
CVE-2025-43859
was published
for
h11
(pip)
Apr 24, 2025
Duplicate Advisory: Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
Moderate
GHSA-4p4h-9gvq-7xfg
was published
for
picklescan
(pip)
Apr 24, 2025
•
withdrawn
LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py
Moderate
CVE-2025-46567
was published
for
llamafactory
(pip)
Apr 23, 2025
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
Critical
GHSA-ggpf-24jw-3fcw
was published
for
vllm
(pip)
Apr 23, 2025
OctoPrint Authenticated Reverse Proxy Page Authentication Bypass
Moderate
CVE-2025-32788
was published
for
octoprint
(pip)
Apr 22, 2025
youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization
High
GHSA-22fp-mf44-f2mq
was published
for
youtube-dl
(pip)
Apr 18, 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
Critical
CVE-2025-32434
was published
for
torch
(pip)
Apr 18, 2025
Rasa Pro Missing Authentication For Voice Connector APIs
Moderate
CVE-2025-32377
was published
for
rasa-pro
(pip)
Apr 17, 2025
Pycel allows code injection via a crafted formula
High
CVE-2024-53924
was published
for
pycel
(pip)
Apr 17, 2025
ProTip!
Advisories are also available from the
GraphQL API