GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,026
Maven
5,000+
npm
4,763
NuGet
824
pip
4,366
Pub
12
RubyGems
987
Rust
1,143
Swift
50
Unreviewed advisories
All unreviewed
5,000+
1,778 advisories
Filter by severity
Cowrie has a SSRF vulnerability in wget/curl emulation enabling DDoS amplification
Moderate
CVE-2025-34469
was published
for
cowrie
(pip)
Dec 20, 2025
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO
Moderate
CVE-2025-68481
was published
for
fastapi-users
(pip)
Dec 19, 2025
FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation
Moderate
CVE-2025-14546
was published
for
fastapi-sso
(pip)
Dec 19, 2025
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
Moderate
CVE-2025-68463
was published
for
biopython
(pip)
Dec 18, 2025
mcp-server-git has missing path validation when using --repository flag
Moderate
CVE-2025-68145
was published
for
mcp-server-git
(pip)
Dec 17, 2025
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Moderate
CVE-2025-68144
was published
for
mcp-server-git
(pip)
Dec 17, 2025
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Moderate
CVE-2025-68143
was published
for
mcp-server-git
(pip)
Dec 17, 2025
Duplicate Advisory: python-jose denial of service via compressed JWE content
Moderate
CVE-2024-29370
was published
for
python-jose
(pip)
Dec 17, 2025
•
withdrawn
filelock has a TOCTOU race condition which allows symlink attacks during lock file creation
Moderate
CVE-2025-68146
was published
for
filelock
(pip)
Dec 16, 2025
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)
Moderate
CVE-2025-67715
was published
for
Weblate
(pip)
Dec 15, 2025
Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration
Moderate
CVE-2025-67492
was published
for
Weblate
(pip)
Dec 15, 2025
django-allauth's Okta and NetIQ implementations used a mutable identifier for authorization decisions
Moderate
CVE-2025-65431
was published
for
django-allauth
(pip)
Dec 15, 2025
django-allauth does not reject access tokens for inactive users
Moderate
CVE-2025-65430
was published
for
django-allauth
(pip)
Dec 15, 2025
Apache Airflow exposes secret values to authenticated UI users via rendered templates
Moderate
CVE-2025-66388
was published
for
apache-airflow
(pip)
Dec 15, 2025
Pyrofork has a Path Traversal in download_media Method
Moderate
CVE-2025-67720
was published
for
pyrofork
(pip)
Dec 10, 2025
HTTP/HTTPS Traffic Interception Bypass in mad-proxy
Moderate
CVE-2025-67485
was published
for
mad-proxy
(pip)
Dec 9, 2025
Open Redirect Vulnerability in Taguette
Moderate
CVE-2025-67502
was published
for
taguette
(pip)
Dec 9, 2025
NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
Moderate
CVE-2025-66470
was published
for
nicegui
(pip)
Dec 8, 2025
NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
Moderate
CVE-2025-66469
was published
for
nicegui
(pip)
Dec 8, 2025
ComposioHQ has a directory traversal vulnerability
Moderate
CVE-2025-56427
was published
for
composio
(pip)
Dec 4, 2025
Ansible Community General Collection is vulnerable to exposure of sensitive information
Moderate
CVE-2025-14010
was published
for
ansible
(pip)
Dec 4, 2025
Django is vulnerable to SQL injection in column aliases
Moderate
CVE-2025-13372
was published
for
Django
(pip)
Dec 2, 2025
Django is vulnerable to DoS via XML serializer text extraction
Moderate
CVE-2025-64460
was published
for
Django
(pip)
Dec 2, 2025
arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
Moderate
CVE-2025-66454
was published
for
arcade-mcp-server
(pip)
Dec 2, 2025
ProTip!
Advisories are also available from the
GraphQL API