GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
10,551 advisories
Filter by severity
Picklescan is missing detection when calling built-in python idlelib.run.Executive.runcode
Moderate
GHSA-m869-42cg-3xwr
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan is missing detection when calling built-in python lib2to3.pgen2.pgen.ParserGenerator.make_label
Moderate
GHSA-p9w7-82w4-7q8m
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan is missing detection when calling built-in python ensurepip._run_pip
Moderate
GHSA-xp4f-hrf8-rxw7
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan is missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_autograd_prof
Moderate
GHSA-4whj-rm5r-c2v8
was published
for
picklescan
(pip)
Aug 26, 2025
GraphQL Armor Max-Depth Plugin Bypass via fragment caching
Moderate
GHSA-224p-v68g-5g8f
was published
for
@escape.tech/graphql-armor-max-depth
(npm)
Aug 26, 2025
GraphQL Armor Max-Depth Plugin Bypass via Introspection Query Obfuscation
Moderate
GHSA-hmfr-rx46-4jx2
was published
for
@escape.tech/graphql-armor-max-depth
(npm)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python library idlelib.calltip.get_entity
Moderate
GHSA-9xph-j2h6-g47v
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip
Moderate
GHSA-8r4j-24qv-fmq9
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter
Moderate
GHSA-cj3c-v495-4xqh
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
Moderate
GHSA-7cq8-mj8x-j263
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity
Moderate
GHSA-6w4w-5w54-rjvr
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
Moderate
GHSA-3vg9-h568-4w9m
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python lib2to3.pgen2.grammar.Grammar.loads
Moderate
GHSA-f54q-57x4-jg88
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python profile.Profile.runctx
Moderate
GHSA-6vqj-c2q5-j97w
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python profile.Profile.run
Moderate
GHSA-x696-vm39-cp64
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python trace.Trace.runctx
Moderate
GHSA-g344-hcph-8vgg
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python trace.Trace.run
Moderate
GHSA-5qwp-399c-mjwf
was published
for
picklescan
(pip)
Aug 26, 2025
traQ Allows Insertion of Sensitive Information into Log File
Moderate
CVE-2025-57813
was published
for
github.com/traPtitech/traQ
(Go)
Aug 26, 2025
Easy!Appointments SQL injection vulnerability
Moderate
CVE-2025-50383
was published
for
alextselegidis/easyappointments
(Composer)
Aug 26, 2025
request-filtering-agent SSRF Bypass via HTTPS Requests to 127.0.0.1
Moderate
CVE-2025-57814
was published
for
request-filtering-agent
(npm)
Aug 25, 2025
mitmproxy binaries embed a vulnerable python-hyper/h2 dependency
Moderate
GHSA-63cx-g855-hvv4
was published
for
mitmproxy
(pip)
Aug 25, 2025
h2 allows HTTP Request Smuggling due to illegal characters in headers
Moderate
CVE-2025-57804
was published
for
h2
(pip)
Aug 25, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
ImageMagick has Undefined Behavior (function-type-mismatch) in CloneSplayTree
Moderate
CVE-2025-55160
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
Liferay Portal allows unrestricted upload of file in the style books component
Moderate
CVE-2025-43766
was published
for
com.liferay:com.liferay.style.book.web
(Maven)
Aug 23, 2025
ProTip!
Advisories are also available from the
GraphQL API