GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
21
Go
2,003
Maven
5,000+
npm
3,713
NuGet
661
pip
3,386
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,412 advisories
Filter by severity
libre-chat Path Traversal vulnerability
Moderate
CVE-2024-52787
was published
for
libre-chat
(pip)
Nov 25, 2024
Mage AI incorrectly gives privileges to users with deleted accounts
Moderate
CVE-2024-45187
was published
for
mage-ai
(pip)
Aug 23, 2024
Apache Airflow: DAG Code and Import Error Permissions Ignored
Moderate
CVE-2024-27906
was published
for
apache-airflow
(pip)
Feb 29, 2024
Twisted vulnerable to NameVirtualHost Host header injection
Moderate
CVE-2022-39348
was published
for
twisted
(pip)
Oct 26, 2022
OpenStack Neutron can use an incorrect ID during policy enforcement
Moderate
CVE-2024-53916
was published
for
neutron
(pip)
Nov 25, 2024
ansible-core Incorrect Authorization vulnerability
Moderate
CVE-2024-9902
was published
for
ansible-core
(pip)
Nov 6, 2024
Sentry improper error handling leaks Application Integration Client Secret
Moderate
CVE-2024-53253
was published
for
sentry
(pip)
Nov 22, 2024
Vyper's raw_call `value=` kwargs not disabled for static and delegate calls
Moderate
CVE-2024-24567
was published
for
vyper
(pip)
Jan 30, 2024
Vyper has incorrect re-entrancy lock when key is empty string
Moderate
CVE-2023-42441
was published
for
vyper
(pip)
Sep 18, 2023
transformers has Insecure Temporary File
Moderate
CVE-2023-2800
was published
for
transformers
(pip)
May 18, 2023
Zope Denial of Service (DoS) vulnerability in ZServer
Moderate
CVE-2010-3198
was published
for
Zope
(pip)
May 17, 2022
PaddlePaddle nullptr dereference in paddle.crop
Moderate
CVE-2023-52312
was published
for
PaddlePaddle
(pip)
Jan 3, 2024
Mayan EDMS DMS XSS vulnerability
Moderate
CVE-2022-47419
was published
for
mayan-edms
(pip)
Feb 8, 2023
Mayan EDMS multiple cross-site scripting (XSS) vulnerabilities
Moderate
CVE-2014-3840
was published
for
mayan-edms
(pip)
May 17, 2022
Ipsilon denial of service via a duplicate SP name
Moderate
CVE-2015-5217
was published
for
ipsilon
(pip)
May 17, 2022
Ipsilon denial of service by deleting a SAML2 Service Provider (SP)
Moderate
CVE-2015-5301
was published
for
ipsilon
(pip)
May 17, 2022
safeurl-python contains Server-Side Request Forgery
Moderate
CVE-2023-24622
was published
for
safeurl-python
(pip)
Jan 27, 2023
OpenStack Glance logs user name and password in cleartext
Moderate
CVE-2013-0212
was published
for
glance
(pip)
May 5, 2022
rdiffweb vulnerable to Open Redirect
Moderate
CVE-2022-3438
was published
for
rdiffweb
(pip)
Oct 10, 2022
rdiffweb allows a new password to be the same as the previous password
Moderate
CVE-2022-3376
was published
for
rdiffweb
(pip)
Oct 6, 2022
Libextractor multiple heap-based buffer overflows
Moderate
CVE-2006-2458
was published
for
extractor
(pip)
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API