GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,618 advisories
Filter by severity
Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites
Moderate
CVE-2023-32323
was published
for
matrix-synapse
(pip)
May 24, 2023
Unintended leak of Proxy-Authorization header in requests
Moderate
CVE-2023-32681
was published
for
requests
(pip)
May 22, 2023
Vyper's nonpayable default functions are sometimes payable
Moderate
CVE-2023-32675
was published
for
vyper
(pip)
May 22, 2023
kiwitcms vulnerable to stored XSS via unrestricted files upload
Moderate
CVE-2023-32686
was published
for
kiwitcms
(pip)
May 22, 2023
transformers has Insecure Temporary File
Moderate
CVE-2023-2800
was published
for
transformers
(pip)
May 18, 2023
Starlette has Path Traversal vulnerability in StaticFiles
Moderate
CVE-2023-29159
was published
for
starlette
(pip)
May 17, 2023
in-toto: PGP trust model not (fully) considered
Moderate
GHSA-jjgp-whrp-gq8m
was published
for
in-toto
(pip)
May 11, 2023
in-toto vulnerable to Configuration Read From Local Directory
Moderate
CVE-2023-32076
was published
for
in-toto
(pip)
May 11, 2023
Apache Airflow vulnerable to stored Cross-site Scripting
Moderate
CVE-2023-29247
was published
for
apache-airflow
(pip)
May 8, 2023
sqlparse contains a regular expression that is vulnerable to Regular Expression Denial of Service
Moderate
CVE-2023-30608
was published
for
sqlparse
(pip)
Apr 21, 2023
pretalx allows path traversal in HTML export
Moderate
CVE-2023-28458
was published
for
pretalx
(pip)
Apr 20, 2023
Modoboa has Weak Password Requirements
Moderate
CVE-2023-2160
was published
for
modoboa
(pip)
Apr 18, 2023
Apache Superset vulnerable to Improper Authorization
Moderate
CVE-2023-27525
was published
for
apache-superset
(pip)
Apr 17, 2023
Improper Restriction of Excessive Authentication Attempts in calibreweb
Moderate
CVE-2022-2525
was published
for
calibreweb
(pip)
Apr 15, 2023
Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation
Moderate
CVE-2023-25392
was published
for
bigflow
(pip)
Apr 10, 2023
Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
Moderate
CVE-2023-28837
was published
for
wagtail
(pip)
Apr 3, 2023
Arbitrary file write in mindsdb when Extracting Tarballs retrieved from a remote location
Moderate
CVE-2022-23522
was published
for
mindsdb
(pip)
Mar 30, 2023
pgAdmin 4 vulnerable to directory traversal
Moderate
CVE-2023-0241
was published
for
pgadmin4
(pip)
Mar 27, 2023
TensorFlow Denial of Service vulnerability
Moderate
CVE-2023-25661
was published
for
tensorflow
(pip)
Mar 27, 2023
redis-py Race Condition vulnerability
Moderate
CVE-2023-28858
was published
for
redis
(pip)
Mar 26, 2023
Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs
Moderate
CVE-2023-1176
was published
for
mlflow
(pip)
Mar 24, 2023
TensorFlow vulnerable to segfault when opening multiframe gif
Moderate
CVE-2023-25667
was published
for
tensorflow
(pip)
Mar 24, 2023
tripleo-ansible may disclose important configuration details from an OpenStack deployment
Moderate
CVE-2022-3101
was published
for
tripleo-ansible
(pip)
Mar 23, 2023
tripleo-ansible may disclose important configuration details from an OpenStack deployment
Moderate
CVE-2022-3146
was published
for
tripleo-ansible
(pip)
Mar 23, 2023
Streamlit publishes previously-patched Cross-site Scripting vulnerability
Moderate
CVE-2023-27494
was published
for
streamlit
(pip)
Mar 17, 2023
ProTip!
Advisories are also available from the
GraphQL API