GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            144 advisories
        Filter by severity
        
      
      
    
                    
                      Eve allows execution of arbitrary code
                    
                      
  Critical
                    
                
                      
                        CVE-2018-8097
                      
                      was published
                        for
                        
                          eve
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      django_make_app is vulnerable to Code Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2017-16764
                      
                      was published
                        for
                        
                          django_make_app
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      Code injection in Danijar Definitions
                    
                      
  High
                    
                
                      
                        CVE-2018-20325
                      
                      was published
                        for
                        
                          definitions
                        
                        (pip)
                      Dec 26, 2018 
                    
                  
                    
                      sqla-yaml-fixtures is vulnerable to Code Injection
                    
                      
  High
                    
                
                      
                        CVE-2019-3575
                      
                      was published
                        for
                        
                          sqla-yaml-fixtures
                        
                        (pip)
                      Jan 4, 2019 
                    
                  
                    
                      ipycache is vulnerable to Code Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2019-7539
                      
                      was published
                        for
                        
                          ipycache
                        
                        (pip)
                      Mar 25, 2019 
                    
                  
                    
                      Eval injection in Supybot/Limnoria
                    
                      
  Critical
                    
                
                      
                        CVE-2019-19010
                      
                      was published
                        for
                        
                          limnoria
                        
                        (pip)
                      Nov 20, 2019 
                    
                  
                    
                      openapi-python-client Arbitrary Code Generation vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2020-15142
                      
                      was published
                        for
                        
                          openapi-python-client
                        
                        (pip)
                      Aug 20, 2020 
                    
                  
                    
                      Remote Code Execution in Red Discord Bot
                    
                      
  High
                    
                
                      
                        CVE-2020-15147
                      
                      was published
                        for
                        
                          Red-DiscordBot
                        
                        (pip)
                      Aug 21, 2020 
                    
                  
                    
                      Arbitrary Code Execution in blazar-dashboard
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-26943
                      
                      was published
                        for
                        
                          blazar-dashboard
                        
                        (pip)
                      Oct 27, 2020 
                    
                  
                    
                      Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-10684
                      
                      was published
                        for
                        
                          ansible
                        
                        (pip)
                      Apr 7, 2021 
                    
                  
                    
                      remote code execution via git repo provider
                    
                      
  Critical
                    
                
                      
                        CVE-2021-39159
                      
                      was published
                        for
                        
                          binderhub
                        
                        (pip)
                      Aug 30, 2021 
                    
                  
                    
                      Improper Input Validation and Command Injection in Ansible
                    
                      
  High
                    
                
                      
                        CVE-2021-3583
                      
                      was published
                        for
                        
                          ansible
                        
                        (pip)
                      Sep 23, 2021 
                    
                  
                    
                      Cobbler before 3.3.0 allows log poisoning
                    
                      
  High
                    
                
                      
                        CVE-2021-40323
                      
                      was published
                        for
                        
                          cobbler
                        
                        (pip)
                      Oct 5, 2021 
                    
                  
                    
                      Code Injection in SLO Generator
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-22557
                      
                      was published
                        for
                        
                          slo-generator
                        
                        (pip)
                      Oct 5, 2021 
                    
                  
                    
                      Code injection in `saved_model_cli`
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-41228
                      
                      was published
                        for
                        
                          tensorflow
                        
                        (pip)
                      Nov 10, 2021 
                    
                  
                    
                      Code injection via unsafe YAML loading
                    
                      
  High
                    
                
                      
                        CVE-2021-43811
                      
                      was published
                        for
                        
                          sockeye
                        
                        (pip)
                      Dec 9, 2021 
                    
                  
                    
                      vault-cli contains possible RCE when reading user-defined data
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-43837
                      
                      was published
                        for
                        
                          vault-cli
                        
                        (pip)
                      Dec 16, 2021 
                    
                  
                    
                      Withdrawn: Code Injection in loguru
                    
                      
  Low
                    
                
                      
                        CVE-2022-0329
                      
                      was published
                        for
                        
                          loguru
                        
                        (pip)
                      Jan 28, 2022 
                        •
                        
                          withdrawn
                    
                  
                    
                      Code Injection in PyTorch Lightning
                    
                      
  Critical
                    
                
                      
                        CVE-2022-0845
                      
                      was published
                        for
                        
                          pytorch-lightning
                        
                        (pip)
                      Mar 6, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API