GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,472
Erlang
33
GitHub Actions
24
Go
2,195
Maven
5,000+
npm
3,841
NuGet
696
pip
3,630
Pub
12
RubyGems
911
Rust
910
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,630 advisories
Filter by severity
AgentScope Path Traversal in /api/file
High
CVE-2024-8438
was published
for
agentscope
(pip)
Mar 20, 2025
Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
High
CVE-2024-8183
was published
for
prefect
(pip)
Mar 20, 2025
Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
High
CVE-2024-10624
was published
for
gradio
(pip)
Mar 20, 2025
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
High
CVE-2024-10569
was published
for
gradio
(pip)
Mar 20, 2025
Gradio Vulnerable to Arbitrary File Deletion
High
CVE-2024-10648
was published
for
gradio
(pip)
Mar 20, 2025
H2O Vulnerable to Arbitrary File Overwrite
High
CVE-2024-8616
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
High
CVE-2024-8062
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
High
CVE-2024-7768
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
High
CVE-2024-7765
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
LiteLLM Vulnerable to Remote Code Execution (RCE)
High
CVE-2024-6825
was published
for
litellm
(pip)
Mar 20, 2025
H2O Vulnerable to Arbitrary File Overwrite via File Export
High
CVE-2024-6854
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Execution of Arbitrary Files
Moderate
CVE-2024-6863
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
High
CVE-2024-10549
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Deserialization of Untrusted Data Vulnerability
Critical
CVE-2024-10553
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
High
CVE-2024-10550
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Moderate
CVE-2025-27018
was published
for
apache-airflow-providers-mysql
(pip)
Mar 19, 2025
Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1944
was published
for
picklescan
(pip)
Mar 10, 2025
H2O Vulnerable to Denial of Service (DoS) and File Write
High
CVE-2024-10572
was published
for
ai.h2o:h2o-ext-xgboost
(Maven)
Mar 20, 2025
Dask Vulnerable to Command Injection
Critical
CVE-2024-10096
was published
for
dask
(pip)
Mar 20, 2025
Aim Vulnerable to Denial of Service (DoS)
High
CVE-2024-10110
was published
for
aim
(pip)
Mar 20, 2025
vLLM denial of service via outlines unbounded cache on disk
Moderate
CVE-2025-29770
was published
for
vllm
(pip)
Mar 19, 2025
LiteLLM Vulnerable to Denial of Service (DoS)
High
CVE-2024-10188
was published
for
litellm
(pip)
Mar 20, 2025
Horovod Vulnerable to Command Injection
Critical
CVE-2024-10190
was published
for
horovod
(pip)
Mar 20, 2025
Apache Spark UI can allow impersonation if ACLs enabled
High
CVE-2022-33891
was published
for
org.apache.spark:spark-parent_2.12
(Maven)
Jul 19, 2022
ProTip!
Advisories are also available from the
GraphQL API