GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,781
Maven
5,000+
npm
4,386
NuGet
772
pip
4,164
Pub
12
RubyGems
965
Rust
1,073
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,586 advisories
Filter by severity
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
High
GHSA-955r-x9j8-7rhh
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
High
GHSA-46h3-79wf-xr6c
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-rrxm-2pvv-m66x
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
High
GHSA-3329-ghmp-jmv5
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
High
GHSA-x843-g5mx-g377
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-r8g5-cgf2-4m4m
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan Bypasses Unsafe Globals Check using pty.spawn
High
GHSA-hgrh-qx5j-jfwx
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan missing detection when calling pty.spawn
High
GHSA-vqmv-47xg-9wpr
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan has Incomplete List of Disallowed Inputs
High
GHSA-84r2-jw7c-4r5q
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan does not block ctypes
High
GHSA-4675-36f9-wf6r
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan vulnerable to Arbitrary File Writing
High
GHSA-m273-6v24-x4m4
was published
for
picklescan
(pip)
Dec 29, 2025
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
High
CVE-2025-67729
was published
for
lmdeploy
(pip)
Dec 26, 2025
FastMCP updated to MCP 1.23+ due to CVE-2025-66416
High
GHSA-rcfx-77hg-w2wv
was published
for
fastmcp
(pip)
Dec 26, 2025
LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method
High
CVE-2025-67644
was published
for
langgraph-checkpoint-sqlite
(pip)
Dec 10, 2025
mechanize Regular Expression Denial of Service vulnerability
High
CVE-2021-32837
was published
for
mechanize
(pip)
Jan 18, 2023
Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devices
High
CVE-2025-13609
was published
for
keylime
(pip)
Nov 24, 2025
Weblate has an arbitrary file read via symbolic links
High
CVE-2025-68279
was published
for
Weblate
(pip)
Dec 18, 2025
Fickling has Code Injection vulnerability via pty.spawn()
High
CVE-2025-67748
was published
for
fickling
(pip)
Dec 15, 2025
Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
High
CVE-2025-67747
was published
for
fickling
(pip)
Dec 15, 2025
ansys-geometry-core OS Command Injection vulnerability
High
CVE-2024-29189
was published
for
ansys-geometry-core
(pip)
Mar 25, 2024
External Control of File Name or Path in Langflow
High
CVE-2025-68478
was published
for
langflow
(pip)
Dec 19, 2025
Langflow vulnerable to Server-Side Request Forgery
High
CVE-2025-68477
was published
for
langflow
(pip)
Dec 19, 2025
nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
High
CVE-2025-53000
was published
for
nbconvert
(pip)
Dec 18, 2025
ProTip!
Advisories are also available from the
GraphQL API