Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

762 advisories

Loading
arpitjain099 Credited to arpitjain099
vLLM: OpenAI auth bypass Critical
CVE-2026-48746 was published for vllm (pip) Jun 16, 2026
x41j Credited to x41j, russellb, and DarkLight1337 russellb russellb
DarkLight1337 DarkLight1337
dash-uploader has a directory traversal vulnerability Critical
CVE-2026-38360 was published for dash-uploader (pip) May 8, 2026
a1ohadance Credited to a1ohadance
Snowflake Connector for Python improperly verifies TLS hostnames Critical
CVE-2026-15925 was published for snowflake-connector-python (pip) Jul 16, 2026
plone.app.event vulnerable to denial of service via iCalendar import Critical
CVE-2026-55247 was published for plone.app.event (pip) Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet Critical
CVE-2026-55248 was published for plone.app.portlets (pip) Aug 28, 2026
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP Critical
CVE-2026-44727 was published for jupyter-server (pip) Jun 18, 2026
pikaball Credited to pikaball, y011d4, 0xHunSec, Yann-P, Carreau, and owen-harborcoat y011d4 y011d4
0xHunSec 0xHunSec Yann-P Yann-P Carreau Carreau owen-harborcoat owen-harborcoat
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) Critical
GHSA-93qj-5q5v-3c2h was published for pantheon-agents (pip) Aug 26, 2026
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
fortress07 Credited to fortress07
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input Critical
CVE-2026-55546 was published for qwed-mcp (pip) Aug 25, 2026
ChromaDB has a code injection vulnerability Critical
CVE-2026-45833 was published for chromadb (pip) Jun 12, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing Critical
CVE-2026-61539 was published for xinference (pip) Aug 21, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
ExecuTorch out-of-bounds access vulnerability Critical
CVE-2025-54950 was published for executorch (Maven) Aug 8, 2025
ExecuTorch heap buffer overflow vulnerability Critical
CVE-2025-54949 was published for executorch (Maven) Aug 8, 2025
ExecuTorch integer overflow vulnerability Critical
CVE-2025-30404 was published for executorch (Maven) Aug 8, 2025
ExecuTorch vulnerable to Heap-based Buffer Overflow Critical
CVE-2025-54951 was published for executorch (Maven) Aug 8, 2025
ExecuTorch integer overflow vulnerability Critical
CVE-2025-30405 was published for executorch (Maven) Aug 8, 2025
surfio has an out-of-bounds read Critical
CVE-2026-55211 was published for surfio (pip) Aug 18, 2026
oddmunds Credited to oddmunds
oddmunds Credited to oddmunds
freeman-bb Credited to freeman-bb, y011d4, ibondarenko1, h1-mrz, and th3cyb3rc0p y011d4 y011d4
ibondarenko1 ibondarenko1 h1-mrz h1-mrz th3cyb3rc0p th3cyb3rc0p
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding Critical
CVE-2026-64825 was published for homeassistant (pip) Jul 21, 2026
PercevalFox Credited to PercevalFox
ProTip! Advisories are also available from the GraphQL API