GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,258
NuGet
760
pip
4,051
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,051 advisories
Filter by severity
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
Low
CVE-2025-64326
was published
for
weblate
(pip)
Nov 5, 2025
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
High
CVE-2025-64439
was published
for
langgraph-checkpoint
(pip)
Nov 5, 2025
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
Moderate
CVE-2025-54941
was published
for
apache-airflow
(pip)
Oct 30, 2025
Django vulnerable to partial directory traversal via archives
Low
CVE-2025-59682
was published
for
django
(pip)
Oct 1, 2025
Django vulnerable to SQL injection in column aliases
High
CVE-2025-59681
was published
for
django
(pip)
Oct 1, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
Apache Airflow: Connection sensitive details exposed to users with READ permissions
Moderate
CVE-2025-54831
was published
for
apache-airflow
(pip)
Sep 26, 2025
Django is subject to SQL injection through its column aliases
High
CVE-2025-57833
was published
for
Django
(pip)
Sep 8, 2025
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Moderate
CVE-2025-55675
was published
for
apache-superset
(pip)
Aug 14, 2025
Apache Superset data query improperly discloses database schema information to low-privileged guest user
Moderate
CVE-2025-55673
was published
for
apache-superset
(pip)
Aug 14, 2025
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
Moderate
CVE-2025-55674
was published
for
apache-superset
(pip)
Aug 14, 2025
Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-55672
was published
for
apache-superset
(pip)
Aug 14, 2025
Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
Moderate
CVE-2024-3651
was published
for
idna
(pip)
Apr 11, 2024
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
Critical
CVE-2025-64459
was published
for
django
(pip)
Nov 5, 2025
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
High
CVE-2025-64458
was published
for
django
(pip)
Nov 5, 2025
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
Moderate
CVE-2025-58337
was published
for
doris-mcp-server
(pip)
Nov 5, 2025
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
High
CVE-2025-11201
was published
for
mlflow
(pip)
Oct 29, 2025
MLflow Weak Password Requirements Authentication Bypass Vulnerability
High
CVE-2025-11200
was published
for
mlflow
(pip)
Oct 29, 2025
Agno session state overwrites between different sessions/users
High
CVE-2025-64168
was published
for
agno
(pip)
Oct 31, 2025
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Moderate
CVE-2023-48795
was published
for
golang.org/x/crypto
(Go)
Dec 18, 2023
Django denial-of-service attack in the intcomma template filter
High
CVE-2024-24680
was published
for
Django
(pip)
Feb 7, 2024
Ansible-core information disclosure flaw
Moderate
CVE-2024-0690
was published
for
ansible-core
(pip)
Feb 6, 2024
Vulnerable OpenSSL included in cryptography wheels
High
CVE-2023-0286
was published
for
cryptography
(pip)
Feb 8, 2023
ProTip!
Advisories are also available from the
GraphQL API