GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
36
GitHub Actions
29
Go
2,336
Maven
5,000+
npm
3,971
NuGet
713
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
131 advisories
Filter by severity
Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
Low
CVE-2025-5321
was published
for
aim
(pip)
May 29, 2025
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
High
CVE-2025-46725
was published
for
langroid
(pip)
May 20, 2025
Langroid has a Code Injection vulnerability in TableChatAgent
Critical
CVE-2025-46724
was published
for
langroid
(pip)
May 20, 2025
Pycel allows code injection via a crafted formula
High
CVE-2024-53924
was published
for
pycel
(pip)
Apr 17, 2025
Duplicate Advisory: Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
Critical
GHSA-c995-4fw3-j39m
was published
for
langflow
(pip)
Apr 7, 2025
•
withdrawn
InternLM LMDeploy code injection vulnerability
Moderate
CVE-2025-3163
was published
for
lmdeploy
(pip)
Apr 3, 2025
pgAdmin 4 Vulnerable to Remote Code Execution
Critical
CVE-2025-2945
was published
for
pgadmin4
(pip)
Apr 3, 2025
Arbitrary Code Execution via Crafted Keras Config for Model Loading
High
CVE-2025-1550
was published
for
keras
(pip)
Mar 11, 2025
Duplicate Advisory: Keras arbitrary code execution vulnerability
High
GHSA-5478-v2w6-c6q7
was published
for
keras
(pip)
Mar 11, 2025
•
withdrawn
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
High
CVE-2025-25362
was published
for
spacy-llm
(pip)
Mar 5, 2025
Withdrawn Advisory: Command injection in Ray
Critical
CVE-2024-57000
was published
for
ray
(pip)
Feb 12, 2025
•
withdrawn
PandasAI interactive prompt function Remote Code Execution (RCE)
Critical
CVE-2024-12366
was published
for
pandasai
(pip)
Feb 11, 2025
Rasa Allows Remote Code Execution via Remote Model Loading
Critical
CVE-2024-49375
was published
for
rasa
(pip)
Jan 14, 2025
pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
High
CVE-2024-56327
was published
for
pyrage
(pip)
Dec 19, 2024
TorchGeo Remote Code Execution Vulnerability
High
CVE-2024-49048
was published
for
torchgeo
(pip)
Nov 12, 2024
Langflow vulnerable to remote code execution
Moderate
CVE-2024-48061
was published
for
langflow
(pip)
Nov 5, 2024
Flair allows arbitrary code execution
Moderate
CVE-2024-10073
was published
for
flair
(pip)
Oct 17, 2024
sqlitedict insecure deserialization vulnerability
High
CVE-2024-35515
was published
for
sqlitedict
(pip)
Sep 18, 2024
Composio Code Injection Vulnerability
Moderate
CVE-2024-8864
was published
for
composio-core
(pip)
Sep 16, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45851
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45847
was published
for
mindsdb
(pip)
Sep 12, 2024
ProTip!
Advisories are also available from the
GraphQL API