GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,315 advisories
Filter by severity
Untrusted search path under some conditions on Windows allows arbitrary code execution
High
CVE-2024-22190
was published
for
GitPython
(pip)
Jan 10, 2024
fonttools XML External Entity Injection (XXE) Vulnerability
High
CVE-2023-45139
was published
for
fonttools
(pip)
Jan 9, 2024
pyload Unauthenticated Flask Configuration Leakage vulnerability
High
CVE-2024-21644
was published
for
pyload-ng
(pip)
Jan 8, 2024
D-Tale server-side request forgery through Web uploads
High
CVE-2024-21642
was published
for
dtale
(pip)
Jan 5, 2024
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
High
CVE-2023-52323
was published
for
pycryptodome
(pip)
Jan 5, 2024
PaddlePaddle stack overflow in paddle.searchsorted
High
CVE-2023-52304
was published
for
PaddlePaddle
(pip)
Jan 3, 2024
PaddlePaddle stack overflow in paddle.linalg.lu_unpack
High
CVE-2023-52307
was published
for
PaddlePaddle
(pip)
Jan 3, 2024
PaddlePaddle heap buffer overflow in paddle.repeat_interleave
High
CVE-2023-52309
was published
for
PaddlePaddle
(pip)
Jan 3, 2024
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
High
CVE-2023-51449
was published
for
gradio
(pip)
Dec 21, 2023
transformers has a Deserialization of Untrusted Data vulnerability
High
CVE-2023-7018
was published
for
transformers
(pip)
Dec 20, 2023
MLflow Local File Disclosure Vulnerability
High
CVE-2023-6977
was published
for
mlflow
(pip)
Dec 20, 2023
Expired tokens can be renewed without validating the account password
High
GHSA-9wgg-m99q-hhfc
was published
for
emailproxy
(pip)
Dec 19, 2023
Apache Superset incorrect write permissions vulnerability
High
CVE-2023-49734
was published
for
apache-superset
(pip)
Dec 19, 2023
mlflow Command Injection vulnerability
High
CVE-2023-6940
was published
for
mlflow
(pip)
Dec 19, 2023
GitHub Security Lab (GHSL) Vulnerability Report: Arbitary write GHSL-2023-182
High
CVE-2023-50731
was published
for
mindsdb
(pip)
Dec 15, 2023
incorrect storage layout for contracts containing large arrays
High
CVE-2023-46247
was published
for
vyper
(pip)
Dec 13, 2023
Local Privilege Escalation in Windows
High
CVE-2023-49797
was published
for
pyinstaller
(pip)
Dec 9, 2023
Cookie leakage between different users in fastapi-proxy-lib
High
GHSA-7vwr-g6pm-9hc8
was published
for
fastapi-proxy-lib
(pip)
Dec 1, 2023
Apache Superset - Elevation of Privilege
High
CVE-2023-40610
was published
for
apache-superset
(pip)
Nov 28, 2023
ProTip!
Advisories are also available from the
GraphQL API