GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,829
Erlang
36
GitHub Actions
33
Go
2,446
Maven
5,000+
npm
4,065
NuGet
723
pip
3,866
Pub
12
RubyGems
943
Rust
1,009
Swift
39
Unreviewed advisories
All unreviewed
5,000+
497 advisories
Filter by severity
ExecuTorch heap buffer overflow vulnerability
Critical
CVE-2025-54949
was published
for
executorch
(pip)
Aug 8, 2025
ExecuTorch vulnerable to Heap-based Buffer Overflow
Critical
CVE-2025-54951
was published
for
executorch
(pip)
Aug 8, 2025
ExecuTorch out-of-bounds access vulnerability
Critical
CVE-2025-54950
was published
for
executorch
(pip)
Aug 8, 2025
ExecuTorch integer overflow vulnerability
Critical
CVE-2025-30405
was published
for
executorch
(pip)
Aug 8, 2025
ExecuTorch integer overflow vulnerability
Critical
CVE-2025-30404
was published
for
executorch
(pip)
Aug 8, 2025
pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
Critical
CVE-2025-54802
was published
for
pyload-ng
(pip)
Aug 4, 2025
num2words subjected to phishing attack, two versions published containing malware
Critical
GHSA-jxr6-qrxx-2ph2
was published
for
num2words
(pip)
Jul 31, 2025
BentoML SSRF Vulnerability in File Upload Processing
Critical
CVE-2025-54381
was published
for
bentoml
(pip)
Jul 29, 2025
smolagents has Sandbox Escape Vulnerability in the local_python_executor.py Module
Critical
CVE-2025-5120
was published
for
smolagents
(pip)
Jul 27, 2025
pyLoad vulnerable to XSS through insecure CAPTCHA
Critical
CVE-2025-53890
was published
for
pyload-ng
(pip)
Jul 15, 2025
Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperator
Critical
CVE-2025-50213
was published
for
apache-airflow-providers-snowflake
(pip)
Jun 26, 2025
rfc3161-client has insufficient verification for timestamp response signatures
Critical
CVE-2025-52556
was published
for
rfc3161-client
(pip)
Jun 20, 2025
Salt vulnerable to directory traversal attack in file receiving method
Critical
CVE-2024-38824
was published
for
salt
(pip)
Jun 13, 2025
BackendAI Missing Authentication for Critical Function
Critical
CVE-2025-49652
was published
for
backend.ai
(pip)
Jun 9, 2025
llama_index vulnerable to SQL Injection
Critical
CVE-2025-1793
was published
for
llama-index
(pip)
Jun 5, 2025
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
Critical
CVE-2025-47277
was published
for
vllm
(pip)
May 20, 2025
Langroid has a Code Injection vulnerability in TableChatAgent
Critical
CVE-2025-46724
was published
for
langroid
(pip)
May 20, 2025
Apache IoTDB Vulnerable to Remote Code Execution
Critical
CVE-2024-24780
was published
for
apache-iotdb
(Maven)
May 14, 2025
Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL
Critical
CVE-2025-47241
was published
for
browser-use
(pip)
May 5, 2025
Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URL
Critical
GHSA-f54f-hr32-586f
was published
for
browser-use
(pip)
May 3, 2025
•
withdrawn
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
Critical
CVE-2025-32444
was published
for
vllm
(pip)
Apr 29, 2025
h11 accepts some malformed Chunked-Encoding bodies
Critical
CVE-2025-43859
was published
for
h11
(pip)
Apr 24, 2025
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
Critical
GHSA-ggpf-24jw-3fcw
was published
for
vllm
(pip)
Apr 23, 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
Critical
CVE-2025-32434
was published
for
pytorch
(pip)
Apr 18, 2025
ProTip!
Advisories are also available from the
GraphQL API