GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,971
Maven
5,000+
npm
4,616
NuGet
788
pip
4,316
Pub
12
RubyGems
984
Rust
1,126
Swift
49
Unreviewed advisories
All unreviewed
5,000+
65 advisories
Filter by severity
Langroid has WAF Bypass Leading to RCE in TableChatAgent
Critical
CVE-2026-25481
was published
for
langroid
(pip)
Feb 2, 2026
Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter
Critical
CVE-2026-26216
was published
for
Crawl4AI
(pip)
Jan 16, 2026
Salesforce Uni2TS has a Code Injection vulnerability
Critical
CVE-2026-22584
was published
for
uni2ts
(pip)
Jan 10, 2026
pgadmin4 has a Meta-Command Filter Command Execution
Critical
CVE-2025-13780
was published
for
pgadmin4
(pip)
Dec 11, 2025
Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
Critical
CVE-2025-62593
was published
for
ray
(pip)
Nov 26, 2025
pgAdmin4 vulnerable to Remote Code Execution (RCE) when running in server mode
Critical
CVE-2025-12762
was published
for
pgadmin4
(pip)
Nov 13, 2025
smolagents has Sandbox Escape Vulnerability in the local_python_executor.py Module
Critical
CVE-2025-5120
was published
for
smolagents
(pip)
Jul 27, 2025
pyLoad vulnerable to XSS through insecure CAPTCHA
Critical
CVE-2025-53890
was published
for
pyload-ng
(pip)
Jul 15, 2025
Langroid has a Code Injection vulnerability in TableChatAgent
Critical
CVE-2025-46724
was published
for
langroid
(pip)
May 20, 2025
Apache IoTDB Vulnerable to Remote Code Execution
Critical
CVE-2024-24780
was published
for
apache-iotdb
(Maven)
May 14, 2025
Duplicate Advisory: Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
Critical
GHSA-c995-4fw3-j39m
was published
for
langflow
(pip)
Apr 7, 2025
•
withdrawn
pgAdmin 4 Vulnerable to Remote Code Execution
Critical
CVE-2025-2945
was published
for
pgadmin4
(pip)
Apr 3, 2025
Withdrawn Advisory: Command injection in Ray
Critical
CVE-2024-57000
was published
for
ray
(pip)
Feb 12, 2025
•
withdrawn
PandasAI interactive prompt function Remote Code Execution (RCE)
Critical
CVE-2024-12366
was published
for
pandasai
(pip)
Feb 11, 2025
Rasa Allows Remote Code Execution via Remote Model Loading
Critical
CVE-2024-49375
was published
for
rasa
(pip)
Jan 14, 2025
pyload-ng vulnerable to RCE with js2py sandbox escape
Critical
CVE-2024-39205
was published
for
pyload-ng
(pip)
Sep 9, 2024
LlamaIndex includes an exec call for `import {cls_name}`
Critical
CVE-2024-45201
was published
for
llama-index-core
(pip)
Aug 22, 2024
langchain-experimental vulnerable to Arbitrary Code Execution
Critical
CVE-2024-21513
was published
for
langchain-experimental
(pip)
Jul 15, 2024
Withdrawn Advisory: Gradio was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py
Critical
CVE-2024-39236
was published
for
Gradio
(pip)
Jul 1, 2024
•
withdrawn
litellm vulnerable to remote code execution based on using eval unsafely
Critical
CVE-2024-5751
was published
for
litellm
(pip)
Jun 27, 2024
vanna vulnerable to remote code execution caused by prompt injection
Critical
CVE-2024-5826
was published
for
vanna
(pip)
Jun 27, 2024
Vanna prompt injection code execution
Critical
CVE-2024-5565
was published
for
vanna
(pip)
May 31, 2024
CraftBeerPi 4 allows arbitrary code execution
Critical
CVE-2024-3955
was published
for
cbpi4
(pip)
May 2, 2024
ProTip!
Advisories are also available from the
GraphQL API