GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
49 advisories
Filter by severity
Duplicate Advisory: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol
High
GHSA-79ph-w9m5-4v5m
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
MLflow: trace API endpoints lack proper authorization validators
High
CVE-2026-8147
was published
for
mlflow
(pip)
Jul 2, 2026
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
High
CVE-2026-54012
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI: Forged chat-file link allows cross-user file read and deletion
High
CVE-2026-54010
was published
for
open-webui
(pip)
Jun 17, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
High
GHSA-7xw9-549r-8jrc
was published
for
DIRAC
(pip)
Jul 13, 2026
pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
High
CVE-2025-7346
was published
for
pyload-ng
(pip)
Jul 8, 2025
langflow has Unauthenticated IDOR on Image Downloads
High
CVE-2026-33484
was published
for
langflow
(pip)
Mar 20, 2026
PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
High
CVE-2026-47405
was published
for
praisonai-platform
(pip)
May 29, 2026
PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
High
CVE-2026-47399
was published
for
praisonai-platform
(pip)
May 29, 2026
OpenCTI: Privilege escalation via graphQL API is abusable by organization admins, due to incorrect ACL on userEdit relationAdd
High
CVE-2026-44730
was published
for
pycti
(pip)
May 28, 2026
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
High
CVE-2024-6221
was published
for
Flask-Cors
(pip)
Aug 18, 2024
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
High
CVE-2026-45301
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI's responses passthrough endpoint lacks access control authorization
High
CVE-2026-44556
was published
for
open-webui
(pip)
May 8, 2026
wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
High
CVE-2026-43977
was published
for
wger
(pip)
May 14, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
High
CVE-2025-67796
was published
for
rdiffweb
(pip)
May 4, 2026
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
High
CVE-2026-34444
was published
for
lupa
(pip)
Apr 7, 2026
wger has Broken Access Control in Global Gym Configuration Update Endpoint
High
CVE-2026-40474
was published
for
wger
(pip)
Apr 16, 2026
Plane is Vulnerable to Unauthenticated Workspace Member Information Disclosure
High
CVE-2026-30244
was published
for
plane
(pip)
Mar 5, 2026
pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
High
CVE-2026-1707
was published
for
pgadmin4
(pip)
Feb 5, 2026
Lollms has an Improper Access Control vulnerability
High
CVE-2026-1117
was published
for
lollms
(pip)
Feb 2, 2026
Authlib has algorithm confusion with asymmetric public keys
High
CVE-2024-37568
was published
for
authlib
(pip)
Jun 9, 2024
Reflex vulnerable to private state fields modification
High
CVE-2025-47425
was published
for
reflex
(pip)
May 15, 2025
Bots using py-cord as Discord API wrapper are vulnerable to shutdowns through remote code execution
High
CVE-2022-36024
was published
for
py-cord
(pip)
Aug 18, 2022
MoinMoin Access Restrictions Bypassed due to improper ACL enforcement
High
CVE-2008-6603
was published
for
moin
(pip)
May 17, 2022
MoinMoin vulnerable to privilege escalation
High
CVE-2008-1937
was published
for
moin
(pip)
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API