GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,761
Maven
5,000+
npm
4,368
NuGet
767
pip
4,137
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,137 advisories
Filter by severity
Weblate is vulnerable to RCE through Git config file overwrite
Critical
CVE-2025-68398
was published
for
Weblate
(pip)
Dec 18, 2025
Weblate has an arbitrary file read via symbolic links
High
CVE-2025-68279
was published
for
Weblate
(pip)
Dec 18, 2025
nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
High
CVE-2025-53000
was published
for
nbconvert
(pip)
Dec 18, 2025
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
Moderate
CVE-2025-68463
was published
for
biopython
(pip)
Dec 18, 2025
mcp-server-git has missing path validation when using --repository flag
Moderate
CVE-2025-68145
was published
for
mcp-server-git
(pip)
Dec 17, 2025
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Moderate
CVE-2025-68144
was published
for
mcp-server-git
(pip)
Dec 17, 2025
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Moderate
CVE-2025-68143
was published
for
mcp-server-git
(pip)
Dec 17, 2025
Duplicate Advisory: python-jose denial of service via compressed JWE content
Moderate
CVE-2024-29370
was published
for
python-jose
(pip)
Dec 17, 2025
•
withdrawn
Apache Airflow Providers Edge3 exposes internal API allowing RCE in web server context
Critical
CVE-2025-67895
was published
for
apache-airflow-providers-edge3
(pip)
Dec 17, 2025
filelock has a TOCTOU race condition which allows symlink attacks during lock file creation
Moderate
CVE-2025-68146
was published
for
filelock
(pip)
Dec 16, 2025
PyMdown Extensions has a ReDOS bug in its Figure Capture extension
Low
CVE-2025-68142
was published
for
pymdown-extensions
(pip)
Dec 16, 2025
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
Fickling has Code Injection vulnerability via pty.spawn()
High
CVE-2025-67748
was published
for
fickling
(pip)
Dec 15, 2025
Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
High
CVE-2025-67747
was published
for
fickling
(pip)
Dec 15, 2025
Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)
Moderate
CVE-2025-67715
was published
for
Weblate
(pip)
Dec 15, 2025
Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration
Moderate
CVE-2025-67492
was published
for
Weblate
(pip)
Dec 15, 2025
Weblate has improper validation upon invitation acceptance
Low
CVE-2025-64725
was published
for
Weblate
(pip)
Dec 15, 2025
django-allauth does not reject access tokens for inactive users
Moderate
CVE-2025-65430
was published
for
django-allauth
(pip)
Dec 15, 2025
django-allauth's Okta and NetIQ implementations used a mutable identifier for authorization decisions
Moderate
CVE-2025-65431
was published
for
django-allauth
(pip)
Dec 15, 2025
Apache Airflow exposes secret values to authenticated UI users via rendered templates
Moderate
CVE-2025-66388
was published
for
apache-airflow
(pip)
Dec 15, 2025
Mayan EDMS is vulnerable to XSS through the /authentication/ file
Low
CVE-2025-14691
was published
for
mayan-edms
(pip)
Dec 15, 2025
Mayan EDMS has an Open Redirect through the /authentication/ file
Low
CVE-2025-14692
was published
for
mayan-edms
(pip)
Dec 15, 2025
Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification
High
CVE-2025-14542
was published
for
utcp
(pip)
Dec 13, 2025
pgadmin4 has a Meta-Command Filter Command Execution
Critical
CVE-2025-13780
was published
for
pgadmin4
(pip)
Dec 11, 2025
Pyrofork has a Path Traversal in download_media Method
Moderate
CVE-2025-67720
was published
for
pyrofork
(pip)
Dec 10, 2025
ProTip!
Advisories are also available from the
GraphQL API