Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

75 advisories

Loading
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs Critical
CVE-2026-73843 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
JanakaSandaruwan Credited to JanakaSandaruwan
vm2 Has a Sandbox Breakout Using Async Generator Critical
CVE-2026-45411 was published for vm2 (npm) May 14, 2026
XmiliaH Credited to XmiliaH
vm2 has Sandbox Breakout Through Null Proto Exception Critical
CVE-2026-44009 was published for vm2 (npm) May 8, 2026
XmiliaH Credited to XmiliaH
vm2 has sandbox breakout via `neutralizeArraySpeciesBatch` Critical
CVE-2026-44008 was published for vm2 (npm) May 8, 2026
XmiliaH Credited to XmiliaH
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an... Critical Unreviewed
CVE-2026-20160 was published Apr 1, 2026
Workers for local Dask clusters mistakenly listened on public interfaces Critical
CVE-2021-42343 was published for distributed (pip) Jul 15, 2022
Duplicate Advisory: Remote code execution in dask Critical
GHSA-j8fq-86c5-5v2r was published for dask (pip) Oct 27, 2021 withdrawn
TigerVNC accessible via the network and not just via a UNIX socket as intended Critical
CVE-2025-32428 was published for jupyter-remote-desktop-proxy (pip) Apr 12, 2025
frejanordsiek Credited to frejanordsiek, consideRatio, and minrk consideRatio consideRatio
minrk minrk
python-docutils allows insecure usage of temporary files Critical
CVE-2009-5042 was published for docutils (pip) Mar 13, 2020
Exposure of Resource to Wrong Sphere in Apache Tomcat Critical
CVE-2017-5648 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) May 13, 2022
sunSUNQ Credited to sunSUNQ and westonsteimel westonsteimel westonsteimel
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (... Critical Unreviewed
CVE-2022-32221 was published Dec 6, 2022
ProTip! Advisories are also available from the GraphQL API