GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            518 advisories
        Filter by severity
        
      
      
    
                    
                      Improper Certificate Validation in Twisted
                    
                      
  Critical
                    
                
                      
                        CVE-2019-12855
                      
                      was published
                        for
                        
                          twisted
                        
                        (pip)
                      Aug 16, 2019 
                    
                  
                    
                      aubio Buffer Overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2018-19800
                      
                      was published
                        for
                        
                          aubio
                        
                        (pip)
                      Jul 26, 2019 
                    
                  
                    
                      Improper Restriction of XML External Entity Reference in ladon
                    
                      
  Critical
                    
                
                      
                        CVE-2019-1010268
                      
                      was published
                        for
                        
                          ladon
                        
                        (pip)
                      Jul 26, 2019 
                    
                  
                    
                      Injection vulnerability that affects ironic-discoverd
                    
                      
  Critical
                    
                
                      
                        CVE-2015-5306
                      
                      was published
                        for
                        
                          ironic-inspector
                        
                        (pip)
                      Jul 5, 2019 
                    
                  
                    
                      Improper Verification of Cryptographic Signature in django-rest-registration
                    
                      
  Critical
                    
                
                      
                        CVE-2019-13177
                      
                      was published
                        for
                        
                          django-rest-registration
                        
                        (pip)
                      Jul 2, 2019 
                    
                  
                    
                      Improper Authentication in Buildbot
                    
                      
  Critical
                    
                
                      
                        CVE-2019-12300
                      
                      was published
                        for
                        
                          buildbot
                        
                        (pip)
                      May 29, 2019 
                    
                  
                    
                      Integer Overflow or Wraparound in Google TensorFlow
                    
                      
  Critical
                    
                
                      
                        CVE-2018-7575
                      
                      was published
                        for
                        
                          tensorflow
                        
                        (pip)
                      Apr 30, 2019 
                    
                  
                    
                      SQLAlchemy vulnerable to SQL Injection via order_by parameter
                    
                      
  Critical
                    
                
                      
                        CVE-2019-7164
                      
                      was published
                        for
                        
                          SQLAlchemy
                        
                        (pip)
                      Apr 16, 2019 
                    
                  
                    
                      SQLAlchemy is vulnerable to SQL Injection via group_by parameter 
                    
                      
  Critical
                    
                
                      
                        CVE-2019-7548
                      
                      was published
                        for
                        
                          SQLAlchemy
                        
                        (pip)
                      Apr 16, 2019 
                    
                  
                    
                      splunk-sdk does not properly verify untrusted TLS server certificates
                    
                      
  Critical
                    
                
                      
                        CVE-2019-5729
                      
                      was published
                        for
                        
                          splunk-sdk
                        
                        (pip)
                      Mar 25, 2019 
                    
                  
                    
                      ipycache is vulnerable to Code Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2019-7539
                      
                      was published
                        for
                        
                          ipycache
                        
                        (pip)
                      Mar 25, 2019 
                    
                  
                    
                      Apache Airflow vulnerable to XSS
                    
                      
  Critical
                    
                
                      
                        CVE-2017-17836
                      
                      was published
                        for
                        
                          apache-airflow
                        
                        (pip)
                      Jan 25, 2019 
                    
                  
                    
                      modulemd uses an unsafe function for processing externally provided data
                    
                      
  Critical
                    
                
                      
                        CVE-2017-1002157
                      
                      was published
                        for
                        
                          modulemd
                        
                        (pip)
                      Jan 17, 2019 
                    
                  
                    
                      Bleach URI Scheme Restriction Bypass
                    
                      
  Critical
                    
                
                      
                        CVE-2018-7753
                      
                      was published
                        for
                        
                          bleach
                        
                        (pip)
                      Jan 4, 2019 
                    
                  
                    
                      PyYAML insecurely deserializes YAML strings leading to arbitrary code execution
                    
                      
  Critical
                    
                
                      
                        CVE-2017-18342
                      
                      was published
                        for
                        
                          pyyaml
                        
                        (pip)
                      Jan 4, 2019 
                    
                  
                    
                      Exposure of Sensitive Information to an Unauthorized Actor in urllib3
                    
                      
  Critical
                    
                
                      
                        CVE-2018-20060
                      
                      was published
                        for
                        
                          urllib3
                        
                        (pip)
                      Dec 12, 2018 
                    
                  
                    
                      Deserialization of Untrusted Data in superset
                    
                      
  Critical
                    
                
                      
                        CVE-2018-8021
                      
                      was published
                        for
                        
                          superset
                        
                        (pip)
                      Nov 9, 2018 
                    
                  
                    
                      python-gnupg vulnerable to shell injection
                    
                      
  Critical
                    
                
                      
                        CVE-2014-1929
                      
                      was published
                        for
                        
                          python-gnupg
                        
                        (pip)
                      Nov 6, 2018 
                    
                  
                    
                      Ansible fails to cache SSH host keys
                    
                      
  Critical
                    
                
                      
                        CVE-2013-2233
                      
                      was published
                        for
                        
                          ansible
                        
                        (pip)
                      Oct 10, 2018 
                    
                  
                    
                      Ansible fails to properly sanitize fact variables sent from the Ansible controller
                    
                      
  Critical
                    
                
                      
                        CVE-2016-8628
                      
                      was published
                        for
                        
                          ansible
                        
                        (pip)
                      Oct 10, 2018 
                    
                  
                    
                      Ansible is vulnerable to an improper input validation in Ansible's handling of data sent from client systems
                    
                      
  Critical
                    
                
                      
                        CVE-2016-9587
                      
                      was published
                        for
                        
                          ansible
                        
                        (pip)
                      Oct 10, 2018 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API