GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
92
GitHub Actions
54
Go
4,217
Maven
5,000+
npm
5,000+
NuGet
1,021
pip
5,000+
Pub
13
RubyGems
1,103
Rust
1,443
Swift
61
Unreviewed advisories
All unreviewed
5,000+
28 advisories
Filter by severity
Apache Superset vulnerable to Injection
Moderate
CVE-2022-43720
was published
for
apache-superset
(pip)
Jan 16, 2023
pyload Log Injection vulnerability
Moderate
CVE-2024-21645
was published
for
pyload-ng
(pip)
Jan 8, 2024
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Moderate
CVE-2024-45595
was published
for
dtale
(pip)
Sep 10, 2024
D-Tale Command Execution Vulnerability
Moderate
CVE-2024-8862
was published
for
dtale
(pip)
Sep 16, 2024
Invenio-App vulnerable to host header injection attack
Moderate
CVE-2019-1020006
was published
for
invenio-app
(pip)
Jul 16, 2019
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
Moderate
CVE-2021-43818
was published
for
lxml
(pip)
Dec 13, 2021
HTML injection in email and account expiry notifications
Moderate
CVE-2021-21333
was published
for
matrix-synapse
(pip)
Mar 26, 2021
OctoPrint vulnerable to Special Element Injection
Moderate
CVE-2022-3607
was published
for
OctoPrint
(pip)
Oct 19, 2022
Radicale regex metacharacters injection in the user name
Moderate
CVE-2015-8748
was published
for
Radicale
(pip)
May 17, 2022
Remote Code Execution in Red Discord Bot
Moderate
CVE-2020-15140
was published
for
Red-DiscordBot
(pip)
Aug 21, 2020
SQLFluff users with access to config file, using `libary_path` may call arbitrary python code
Moderate
CVE-2023-36830
was published
for
sqlfluff
(pip)
Jul 6, 2023
vault-cli contains possible RCE when reading user-defined data
Moderate
CVE-2021-43837
was published
for
vault-cli
(pip)
Dec 16, 2021
Apache Airflow Potential Cross-site Scripting Vulnerability
Moderate
CVE-2024-39863
was published
for
apache-airflow
(pip)
Jul 17, 2024
InternLM LMDeploy code injection vulnerability
Moderate
CVE-2025-3163
was published
for
lmdeploy
(pip)
Apr 3, 2025
Apache Spark vulnerable to Log Injection
Moderate
CVE-2022-31777
was published
for
org.apache.spark:spark-core_2.10
(Maven)
Nov 1, 2022
records-mover Injection vulnerability
Moderate
CVE-2023-7333
was published
for
records-mover
(pip)
Jan 8, 2026
Tornado has incomplete validation of cookie attributes
Moderate
GHSA-78cv-mqj4-43f7
was published
for
tornado
(pip)
Mar 11, 2026
Vanna has a SQL injection in the remove_training_data function
Moderate
CVE-2026-4229
was published
for
vanna
(pip)
Mar 16, 2026
MetaGPT has an eval injection in metagpt/strategy/tot.py
Moderate
CVE-2026-6110
was published
for
metagpt
(pip)
Apr 12, 2026
AgentScope Vulnerable to Remote Code Injection
Moderate
CVE-2026-6603
was published
for
agentscope
(pip)
Apr 20, 2026
sqlite-mcp has an Injection issue
Moderate
CVE-2026-7206
was published
for
sqlite-mcp
(pip)
Apr 28, 2026
ProTip!
Advisories are also available from the
GraphQL API