GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,311
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,448 advisories
Filter by severity
GluonCV Arbitrary File Write via TarSlip
High
CVE-2024-12216
was published
for
gluoncv
(pip)
Mar 20, 2025
InvokeAI Uncontrolled Resource Consumption vulnerability
High
CVE-2024-11043
was published
for
InvokeAI
(pip)
Mar 20, 2025
FastChat Denial of Service vulnerability
High
CVE-2024-10912
was published
for
fschat
(pip)
Mar 20, 2025
FastChat Uncontrolled Resource Consumption vulnerability
High
CVE-2024-10907
was published
for
fschat
(pip)
Mar 20, 2025
HyperLPR Denial of Service vulnerability
High
CVE-2024-10713
was published
for
hyperlpr3
(pip)
Mar 20, 2025
InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
High
CVE-2024-10821
was published
for
InvokeAI
(pip)
Mar 20, 2025
DB-GPT Uncontrolled Resource Consumption vulnerability
High
CVE-2024-10829
was published
for
dbgpt
(pip)
Mar 20, 2025
DB-GPT vulnerable to Cross-Site Request Forgery
High
CVE-2024-10906
was published
for
dbgpt
(pip)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
High
CVE-2024-10549
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
High
CVE-2024-10550
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
High
CVE-2024-10569
was published
for
gradio
(pip)
Mar 20, 2025
Gradio Vulnerable to Arbitrary File Deletion
High
CVE-2024-10648
was published
for
gradio
(pip)
Mar 20, 2025
Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
High
CVE-2024-10624
was published
for
gradio
(pip)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) and File Write
High
CVE-2024-10572
was published
for
ai.h2o:h2o-ext-xgboost
(Maven)
Mar 20, 2025
Aim Vulnerable to Denial of Service (DoS)
High
CVE-2024-10110
was published
for
aim
(pip)
Mar 20, 2025
LiteLLM Vulnerable to Denial of Service (DoS)
High
CVE-2024-10188
was published
for
litellm
(pip)
Mar 20, 2025
PostQuantum-Feldman-VSS'S Dependency Vulnerability in gmpy2 Leading to Interpreter Crash
High
GHSA-v432-7f47-9g94
was published
for
PostQuantum-Feldman-VSS
(pip)
Mar 17, 2025
Arbitrary Code Execution via Crafted Keras Config for Model Loading
High
CVE-2025-1550
was published
for
keras
(pip)
Mar 11, 2025
Duplicate Advisory: Keras arbitrary code execution vulnerability
High
GHSA-5478-v2w6-c6q7
was published
for
keras
(pip)
Mar 11, 2025
•
withdrawn
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
High
CVE-2025-25362
was published
for
spacy-llm
(pip)
Mar 5, 2025
dmlc/dgl Vulnerable to Remote Code Execution by Pickle Deserialization via rpc.recv_request()
High
GHSA-3x5x-fw77-g54c
was published
for
dgl
(pip)
Mar 5, 2025
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
High
CVE-2025-27154
was published
for
spotipy
(pip)
Feb 28, 2025
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
High
CVE-2025-1403
was published
for
qiskit
(pip)
Feb 21, 2025
ProTip!
Advisories are also available from the
GraphQL API