GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,958
Maven
5,000+
npm
4,609
NuGet
788
pip
4,309
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
164 advisories
Filter by severity
Langroid has WAF Bypass Leading to RCE in TableChatAgent
Critical
CVE-2026-25481
was published
for
langroid
(pip)
Feb 2, 2026
Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
High
CVE-2025-62348
was published
for
salt
(pip)
Jan 30, 2026
AutoGPT is Vulnerable to RCE via Disabled Block Execution
High
CVE-2026-24780
was published
for
agpt
(pip)
Jan 29, 2026
PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files
High
CVE-2026-24747
was published
for
pytorch
(pip)
Jan 27, 2026
Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization
Moderate
CVE-2026-23946
was published
for
tendenci
(pip)
Jan 21, 2026
vLLM affected by RCE via auto_map dynamic module loading during model initialization
High
CVE-2026-22807
was published
for
vllm
(pip)
Jan 21, 2026
Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter
Critical
GHSA-5882-5rx9-xgxp
was published
for
Crawl4AI
(pip)
Jan 16, 2026
Salesforce Uni2TS has a Code Injection vulnerability
Critical
CVE-2026-22584
was published
for
uni2ts
(pip)
Jan 10, 2026
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
High
GHSA-46h3-79wf-xr6c
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
High
GHSA-955r-x9j8-7rhh
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
Moderate
GHSA-6556-fwc2-fg2p
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-rrxm-2pvv-m66x
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
Moderate
GHSA-cffc-mxrf-mhh4
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
High
GHSA-3329-ghmp-jmv5
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
High
GHSA-x843-g5mx-g377
was published
for
picklescan
(pip)
Dec 29, 2025
Fickling has Code Injection vulnerability via pty.spawn()
High
CVE-2025-67748
was published
for
fickling
(pip)
Dec 15, 2025
pgadmin4 has a Meta-Command Filter Command Execution
Critical
CVE-2025-13780
was published
for
pgadmin4
(pip)
Dec 11, 2025
vLLM vulnerable to remote code execution via transformers_utils/get_config
High
CVE-2025-66448
was published
for
vllm
(pip)
Dec 2, 2025
Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
Critical
CVE-2025-62593
was published
for
ray
(pip)
Nov 26, 2025
pgAdmin4 vulnerable to Remote Code Execution (RCE) when running in server mode
Critical
CVE-2025-12762
was published
for
pgadmin4
(pip)
Nov 13, 2025
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
PyInstaller has local privilege escalation vulnerability
High
CVE-2025-59042
was published
for
pyinstaller
(pip)
Sep 10, 2025
Pyload log Injection via API /json/add_package in add_name parameter
Moderate
GHSA-3wwm-hjv7-23r3
was published
for
pyload-ng
(pip)
Jul 30, 2025
smolagents has Sandbox Escape Vulnerability in the local_python_executor.py Module
Critical
CVE-2025-5120
was published
for
smolagents
(pip)
Jul 27, 2025
pyLoad vulnerable to XSS through insecure CAPTCHA
Critical
CVE-2025-53890
was published
for
pyload-ng
(pip)
Jul 15, 2025
ProTip!
Advisories are also available from the
GraphQL API