GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,051
Maven
5,000+
npm
4,791
NuGet
825
pip
4,389
Pub
12
RubyGems
988
Rust
1,145
Swift
50
Unreviewed advisories
All unreviewed
5,000+
1,792 advisories
Filter by severity
Gradio has an Open Redirect in its OAuth Flow
Moderate
CVE-2026-28415
was published
for
gradio
(pip)
Mar 1, 2026
Indico has a missing access check in the event series management API
Moderate
CVE-2026-28352
was published
for
indico
(pip)
Mar 1, 2026
pypdf: Manipulated RunLengthDecode streams can exhaust RAM
Moderate
CVE-2026-28351
was published
for
pypdf
(pip)
Feb 28, 2026
AWS CLI: cli_history database does not restrict file permissions on Unix systems
Moderate
GHSA-747p-wmpv-9c78
was published
for
awscli
(pip)
Feb 27, 2026
Copyparty vulnerable to reflected XSS via setck parameter
Moderate
CVE-2026-27948
was published
for
copyparty
(pip)
Feb 26, 2026
wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
Moderate
CVE-2026-27839
was published
for
wger
(pip)
Feb 26, 2026
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
Moderate
CVE-2026-27835
was published
for
wger
(pip)
Feb 26, 2026
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
Moderate
CVE-2026-27888
was published
for
pypdf
(pip)
Feb 26, 2026
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Moderate
CVE-2026-27457
was published
for
weblate
(pip)
Feb 26, 2026
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
Moderate
CVE-2026-27809
was published
for
psd-tools
(pip)
Feb 26, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Moderate
CVE-2026-27735
was published
for
mcp-server-git
(pip)
Feb 26, 2026
LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution
Moderate
CVE-2026-27794
was published
for
langgraph-checkpoint
(pip)
Feb 25, 2026
zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service
Moderate
CVE-2026-27695
was published
for
zae-limiter
(pip)
Feb 25, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
Moderate
CVE-2026-25736
was published
for
rucio-webui
(pip)
Feb 25, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
Moderate
CVE-2026-25735
was published
for
rucio-webui
(pip)
Feb 25, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
Moderate
CVE-2026-25734
was published
for
rucio-webui
(pip)
Feb 25, 2026
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
Moderate
CVE-2026-27645
was published
for
changedetection.io
(pip)
Feb 25, 2026
Rucio WebUI has Username Enumeration via Login Error Message
Moderate
CVE-2026-25138
was published
for
rucio-webui
(pip)
Feb 25, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
Moderate
CVE-2026-26717
was published
for
richie
(pip)
Feb 25, 2026
Fickling has safety check bypass via REDUCE+BUILD opcode sequence
Moderate
GHSA-mhc9-48gj-9gp3
was published
for
fickling
(pip)
Feb 25, 2026
Isso affected by Stored XSS via comment website field
Moderate
CVE-2026-27469
was published
for
isso
(pip)
Feb 24, 2026
Apache Superset allows privileged users to conduct error-based SQL Injection
Moderate
CVE-2026-23980
was published
for
apache-superset
(pip)
Feb 24, 2026
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Moderate
CVE-2026-23969
was published
for
apache-superset
(pip)
Feb 24, 2026
Apache Airflow exposes sensitive information in its log files
Moderate
CVE-2025-27555
was published
for
apache-airflow
(pip)
Feb 24, 2026
Apache Airflow error reporting may expose full kwargs
Moderate
CVE-2025-65995
was published
for
apache-airflow
(pip)
Feb 21, 2026
ProTip!
Advisories are also available from the
GraphQL API