GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,607
Maven
5,000+
npm
4,251
NuGet
757
pip
4,016
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,016 advisories
Filter by severity
BBOT's gitlab.py exposes globally configured "gitlab" API key
Moderate
CVE-2025-10282
was published
for
bbot
(pip)
Oct 27, 2025
pg8000 SQL injection vulnerability via a specially crafted Python list input
High
CVE-2025-61385
was published
for
pg8000
(pip)
Oct 27, 2025
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
High
CVE-2025-8709
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 26, 2025
pypdf can exhaust RAM via manipulated LZWDecode streams
Moderate
CVE-2025-62708
was published
for
pypdf
(pip)
Oct 22, 2025
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
Moderate
CVE-2025-62707
was published
for
pypdf
(pip)
Oct 22, 2025
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
High
CVE-2025-62611
was published
for
aiomysql
(pip)
Oct 22, 2025
Scapy Session Loading Vulnerable to Arbitrary Code Execution via Untrusted Pickle Deserialization
Moderate
GHSA-cq46-m9x9-j8w2
was published
for
scapy
(pip)
Oct 22, 2025
Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function
Moderate
CVE-2025-11844
was published
for
smolagents
(pip)
Oct 22, 2025
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
Moderate
CVE-2025-62607
was published
for
nautobot-ssot
(pip)
Oct 21, 2025
uv has differential in tar extraction with PAX headers
Low
GHSA-w476-p2h3-79g9
was published
for
uv
(pip)
Oct 21, 2025
Taguette vulnerable to cross-site scripting via tag name, tag description, document name and document description
Moderate
CVE-2025-62528
was published
for
taguette
(pip)
Oct 20, 2025
Taguette password reset link poisoning
High
CVE-2025-62527
was published
for
taguette
(pip)
Oct 20, 2025
Keras framework vulnerable to deserialization of untrusted data
Critical
CVE-2025-49655
was published
for
keras
(pip)
Oct 17, 2025
pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer
Critical
CVE-2025-62515
was published
for
pyquokka
(pip)
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Moderate
CVE-2025-11849
was published
for
Mammoth
(Maven)
Oct 17, 2025
reflex-dev/reflex has an Open Redirect vulnerability
Low
CVE-2025-62379
was published
for
reflex
(pip)
Oct 15, 2025
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
High
CVE-2025-62172
was published
for
homeassistant
(pip)
Oct 14, 2025
llama-index has Insecure Temporary File
High
CVE-2025-7707
was published
for
llama-index
(pip)
Oct 13, 2025
Authlib : JWE zip=DEF decompression bomb enables DoS
Moderate
CVE-2025-62706
was published
for
authlib
(pip)
Oct 10, 2025
python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
Moderate
CVE-2025-61912
was published
for
python-ldap
(pip)
Oct 10, 2025
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
Moderate
CVE-2025-61911
was published
for
python-ldap
(pip)
Oct 10, 2025
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
High
CVE-2025-61920
was published
for
authlib
(pip)
Oct 10, 2025
BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
Critical
CVE-2025-10283
was published
for
bbot
(pip)
Oct 9, 2025
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
Moderate
CVE-2025-10281
was published
for
bbot
(pip)
Oct 9, 2025
BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
Critical
CVE-2025-10284
was published
for
bbot
(pip)
Oct 9, 2025
ProTip!
Advisories are also available from the
GraphQL API