GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
54 advisories
Filter by severity
MindSQL is vulnerable to Code Injection through its ask_db function
Low
CVE-2026-4506
was published
for
mindsql
(pip)
Mar 21, 2026
Vanna has a SQL injection in the remove_training_data function
Moderate
CVE-2026-4229
was published
for
vanna
(pip)
Mar 16, 2026
Tornado has incomplete validation of cookie attributes
Moderate
GHSA-78cv-mqj4-43f7
was published
for
tornado
(pip)
Mar 11, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
High
CVE-2026-27194
was published
for
dtale
(pip)
Feb 19, 2026
records-mover Injection vulnerability
Moderate
CVE-2023-7333
was published
for
records-mover
(pip)
Jan 8, 2026
Apache Spark vulnerable to Log Injection
Moderate
CVE-2022-31777
was published
for
org.apache.spark:spark-core_2.10
(Maven)
Nov 1, 2022
Ankitects Anki arbitrary script execution vulnerability
High
CVE-2024-26020
was published
for
anki
(pip)
Jul 22, 2024
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
InternLM LMDeploy code injection vulnerability
Moderate
CVE-2025-3163
was published
for
lmdeploy
(pip)
Apr 3, 2025
Apache Airflow Potential Cross-site Scripting Vulnerability
Moderate
CVE-2024-39863
was published
for
apache-airflow
(pip)
Jul 17, 2024
vault-cli contains possible RCE when reading user-defined data
Moderate
CVE-2021-43837
was published
for
vault-cli
(pip)
Dec 16, 2021
dbt has an implicit override for built-in materializations from installed packages
Low
CVE-2024-40637
was published
for
dbt-core
(pip)
Jul 17, 2024
Langchain SQL Injection vulnerability
Low
CVE-2024-8309
was published
for
langchain
(pip)
Oct 29, 2024
Langchain SQL Injection vulnerability
Critical
CVE-2023-32785
was published
for
langchain
(pip)
Oct 21, 2023
SQLFluff users with access to config file, using `libary_path` may call arbitrary python code
Moderate
CVE-2023-36830
was published
for
sqlfluff
(pip)
Jul 6, 2023
Remote Code Execution in Red Discord Bot
High
CVE-2020-15147
was published
for
Red-DiscordBot
(pip)
Aug 21, 2020
Remote Code Execution in Red Discord Bot
Moderate
CVE-2020-15140
was published
for
Red-DiscordBot
(pip)
Aug 21, 2020
SaltStack Salt is vulnerable to shell injection via ProxyCommand argument
Critical
CVE-2021-3197
was published
for
salt
(pip)
May 24, 2022
pwntools Server-Side Template Injection (SSTI) vulnerability
Critical
CVE-2020-28468
was published
for
pwntools
(pip)
Apr 20, 2021
Radicale regex metacharacters injection in the user name
Moderate
CVE-2015-8748
was published
for
Radicale
(pip)
May 17, 2022
Arbitrary expression injection in Pillow
Critical
CVE-2022-22817
was published
for
Pillow
(pip)
Jan 12, 2022
ProTip!
Advisories are also available from the
GraphQL API