GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,051
Maven
5,000+
npm
4,791
NuGet
825
pip
4,389
Pub
12
RubyGems
988
Rust
1,145
Swift
50
Unreviewed advisories
All unreviewed
5,000+
4,389 advisories
Filter by severity
Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing
High
CVE-2026-28416
was published
for
gradio
(pip)
Mar 1, 2026
Gradio has an Open Redirect in its OAuth Flow
Moderate
CVE-2026-28415
was published
for
gradio
(pip)
Mar 1, 2026
Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+
High
CVE-2026-28414
was published
for
gradio
(pip)
Mar 1, 2026
Indico has a missing access check in the event series management API
Moderate
CVE-2026-28352
was published
for
indico
(pip)
Mar 1, 2026
Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
Low
CVE-2026-27167
was published
for
gradio
(pip)
Mar 1, 2026
pypdf: Manipulated RunLengthDecode streams can exhaust RAM
Moderate
CVE-2026-28351
was published
for
pypdf
(pip)
Feb 28, 2026
AWS CLI: cli_history database does not restrict file permissions on Unix systems
Moderate
GHSA-747p-wmpv-9c78
was published
for
awscli
(pip)
Feb 27, 2026
Langflow has Remote Code Execution in CSV Agent
Critical
CVE-2026-27966
was published
for
langflow
(pip)
Feb 27, 2026
OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection
Critical
CVE-2026-28370
was published
for
vitrage
(pip)
Feb 27, 2026
Copyparty vulnerable to reflected XSS via setck parameter
Moderate
CVE-2026-27948
was published
for
copyparty
(pip)
Feb 26, 2026
wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
Moderate
CVE-2026-27839
was published
for
wger
(pip)
Feb 26, 2026
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
Low
CVE-2026-27838
was published
for
wger
(pip)
Feb 26, 2026
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
Moderate
CVE-2026-27835
was published
for
wger
(pip)
Feb 26, 2026
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
Moderate
CVE-2026-27888
was published
for
pypdf
(pip)
Feb 26, 2026
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Moderate
CVE-2026-27457
was published
for
weblate
(pip)
Feb 26, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Moderate
CVE-2026-27735
was published
for
mcp-server-git
(pip)
Feb 26, 2026
LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution
Moderate
CVE-2026-27794
was published
for
langgraph-checkpoint
(pip)
Feb 25, 2026
zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service
Moderate
CVE-2026-27695
was published
for
zae-limiter
(pip)
Feb 25, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
Moderate
CVE-2026-25736
was published
for
rucio-webui
(pip)
Feb 25, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
Moderate
CVE-2026-25735
was published
for
rucio-webui
(pip)
Feb 25, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
Moderate
CVE-2026-25734
was published
for
rucio-webui
(pip)
Feb 25, 2026
changedetection.io is Vulnerable to SSRF via Watch URLs
High
CVE-2026-27696
was published
for
changedetection.io
(pip)
Feb 25, 2026
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
Moderate
CVE-2026-27645
was published
for
changedetection.io
(pip)
Feb 25, 2026
Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection
Critical
CVE-2026-27641
was published
for
flask-reuploaded
(pip)
Feb 25, 2026
ProTip!
Advisories are also available from the
GraphQL API