Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,972 advisories

Loading
ogham-mcp had credentials embedded in published PyPI sdists -- Neon postgres URLs and Voyage API key Moderate
GHSA-8pqq-224h-x875 was published for ogham-mcp (pip) May 5, 2026
wlc: print_html outputs API data without HTML escaping Moderate
CVE-2026-42150 was published for wlc (pip) Apr 24, 2026
fg0x0 Credited to fg0x0 and nijel nijel nijel
Pillow has a PDF Parsing Trailer Infinite Loop (DoS) Moderate
CVE-2026-42310 was published for pillow (pip) May 4, 2026
kexinoh Credited to kexinoh
Pillow has an integer overflow when processing fonts Moderate
CVE-2026-42308 was published for pillow (pip) May 4, 2026
Pillow has a heap buffer overflow with nested list coordinates Moderate
CVE-2026-42309 was published for pillow (pip) May 4, 2026
AgentScope Vulnerable to Remote Code Injection Moderate
CVE-2026-6603 was published for agentscope (pip) Apr 20, 2026
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql` Moderate
CVE-2026-42032 was published for ckan (pip) Apr 30, 2026
ddd Credited to ddd
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url Moderate
CVE-2026-41654 was published for weblate (pip) Apr 30, 2026
fg0x0 Credited to fg0x0 and nijel nijel nijel
Weblate Doesn't Invalidate API Token on Password Change Moderate
CVE-2026-41519 was published for weblate (pip) Apr 30, 2026
whatisproblem Credited to whatisproblem and nijel nijel nijel
CKAN has CSRF exemption primed by anonymous requests Moderate
CVE-2026-41255 was published for ckan (pip) Apr 29, 2026
Shirshaw64p Credited to Shirshaw64p
CKAN has no certificate validation on STMP connection Moderate
CVE-2026-41132 was published for ckan (pip) Apr 29, 2026
francisbergin Credited to francisbergin
beets has a Cross-site Scripting vulnerability Moderate
CVE-2026-42052 was published for beets (pip) Apr 29, 2026
FORIMOC Credited to FORIMOC and Yuremin Yuremin Yuremin
AgentScope vulnerable to Server-Side Request Forgery Moderate
CVE-2026-6606 was published for agentscope (pip) Apr 20, 2026
AgentScope vulnerable to Server-Side Request Forgery Moderate
CVE-2026-6605 was published for agentscope (pip) Apr 20, 2026
AgentScope vulnerable to Server-Side Request Forgery Moderate
CVE-2026-6604 was published for agentscope (pip) Apr 20, 2026
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint Moderate
CVE-2026-33866 was published for mlflow (pip) Apr 7, 2026
LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass Moderate
CVE-2026-41481 was published for langchain-text-splitters (pip) Apr 16, 2026
Aeg1sx Credited to Aeg1sx
JupyterHub has an Open Redirect Vulnerability Moderate
CVE-2026-33709 was published for jupyterhub (pip) Apr 3, 2026
RacerZ-fighting Credited to RacerZ-fighting and Fushuling Fushuling Fushuling
pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders Moderate
CVE-2026-41426 was published for pretalx (pip) Apr 18, 2026
markfijneman Credited to markfijneman
Authlib: Cross-site request forging when using cache Moderate
CVE-2026-41425 was published for authlib (pip) Apr 16, 2026
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez Moderate
CVE-2025-68463 was published for biopython (pip) Dec 18, 2025
Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates Moderate
CVE-2026-40602 was published for homeassistant-cli (pip) Apr 16, 2026
heyitsPiyush Credited to heyitsPiyush and fabaff fabaff fabaff
offset Credited to offset
mitmproxy has an LDAP Injection Moderate
CVE-2026-40606 was published for mitmproxy (pip) Apr 14, 2026
yueyueL Credited to yueyueL and mhils mhils mhils
ProTip! Advisories are also available from the GraphQL API