GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            18 advisories
        Filter by severity
        
      
      
    
                    
                      io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout
                    
                      
  High
                    
                
                      
                        CVE-2025-1634
                      
                      was published
                        for
                        
                          io.quarkus:quarkus-resteasy
                        
                        (Maven)
                      Feb 26, 2025 
                    
                  
                    
                      Grafana Spoofing originalUrl of snapshots
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-39324
                      
                      was published
                        for
                        
                          github.com/grafana/grafana
                        
                        (Go)
                      May 14, 2024 
                    
                  
                    
                      LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
                    
                      
  Critical
                    
                
                      
                        CVE-2024-2952
                      
                      was published
                        for
                        
                          litellm
                        
                        (pip)
                      Apr 10, 2024 
                    
                  
                    
                      ESPHome vulnerable to Authentication bypass via Cross site request forgery
                    
                      
  High
                    
                
                      
                        CVE-2024-29019
                      
                      was published
                        for
                        
                          esphome
                        
                        (pip)
                      Mar 21, 2024 
                    
                  
                    
                      Memory leaks in code encrypting and verifying RSA payloads
                    
                      
  High
                    
                
                      
                        CVE-2024-1394
                      
                      was published
                        for
                        
                          github.com/golang-fips/go
                        
                        (Go)
                      Mar 20, 2024 
                    
                  
                    
                      Improper Privilege Management in djangorestframework-simplejwt
                    
                      
  Low
                    
                
                      
                        CVE-2024-22513
                      
                      was published
                        for
                        
                          djangorestframework-simplejwt
                        
                        (pip)
                      Mar 16, 2024 
                    
                  
                    
                      Microsoft Security Advisory CVE-2024-21392: .NET Denial of Service Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-21392
                      
                      was published
                        for
                        
                          Microsoft.NETCore.App.Runtime.linux-arm
                        
                        (NuGet)
                      Mar 12, 2024 
                    
                  
                    
                      Unsafe yaml deserialization in llama-hub
                    
                      
  Critical
                    
                
                      
                        CVE-2024-23730
                      
                      was published
                        for
                        
                          llama-hub
                        
                        (pip)
                      Jan 21, 2024 
                    
                  
                    
                      Insertion of Sensitive Information into Log File in OWASP DependencyCheck
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-23686
                      
                      was published
                        for
                        
                          org.owasp:dependency-check-ant
                        
                        (Maven)
                      Jan 20, 2024 
                    
                  
                    
                      SQL injection in Apache Submarine
                    
                      
  Critical
                    
                
                      
                        CVE-2023-37924
                      
                      was published
                        for
                        
                          apache-submarine
                        
                        (pip)
                      Nov 22, 2023 
                    
                  
                    
                      Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-47037
                      
                      was published
                        for
                        
                          apache-airflow
                        
                        (pip)
                      Nov 12, 2023 
                    
                  
                    
                      PyArrow: Arbitrary code execution when loading a malicious data file
                    
                      
  Critical
                    
                
                      
                        CVE-2023-47248
                      
                      was published
                        for
                        
                          pyarrow
                        
                        (pip)
                      Nov 9, 2023 
                    
                  
                    
                      transmute-core unsafe YAML deserialization vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2023-47204
                      
                      was published
                        for
                        
                          transmute-core
                        
                        (pip)
                      Nov 2, 2023 
                    
                  
                    
                      Apache Ranger Access Restriction Bypass
                    
                      
  High
                    
                
                      
                        CVE-2016-0735
                      
                      was published
                        for
                        
                          org.apache.ranger:ranger
                        
                        (Maven)
                      May 17, 2022 
                    
                  
                    
                      Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
                    
                      
  High
                    
                
                      
                        CVE-2017-5647
                      
                      was published
                        for
                        
                          org.apache.tomcat:tomcat
                        
                        (Maven)
                      May 14, 2022 
                    
                  
                    
                      Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
                    
                      
  High
                    
                
                      
                        CVE-2015-0226
                      
                      was published
                        for
                        
                          org.apache.ws.security:wss4j
                        
                        (Maven)
                      May 14, 2022 
                    
                  
                    
                      Undertow Request Smuggling vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2017-12165
                      
                      was published
                        for
                        
                          io.undertow:undertow-core
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      Spring Data Commons remote code injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2018-1273
                      
                      was published
                        for
                        
                          org.springframework.data:spring-data-commons
                        
                        (Maven)
                      Oct 17, 2018 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API