GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            4,031 advisories
        Filter by severity
        
      
      
    
                    
                      Jupyter Notebook file bypasses sanitization, executes JavaScript
                    
                      
  High
                    
                
                      
                        CVE-2018-8768
                      
                      was published
                        for
                        
                          notebook
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      Arbitrary code using "crafted image file" approach affecting Pillow
                    
                      
  High
                    
                
                      
                        CVE-2016-9190
                      
                      was published
                        for
                        
                          Pillow
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      markdown2 is vulnerable to cross-site scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-5773
                      
                      was published
                        for
                        
                          markdown2
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      Pycrypto generates weak key parameters
                    
                      
  High
                    
                
                      
                        CVE-2018-6594
                      
                      was published
                        for
                        
                          pycrypto
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      Paramiko not properly checking authentication before processing other requests
                    
                      
  Critical
                    
                
                      
                        CVE-2018-7750
                      
                      was published
                        for
                        
                          paramiko
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      Eve allows execution of arbitrary code
                    
                      
  Critical
                    
                
                      
                        CVE-2018-8097
                      
                      was published
                        for
                        
                          eve
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      Koji hub call does not perform correct access checks
                    
                      
  Critical
                    
                
                      
                        CVE-2018-1002150
                      
                      was published
                        for
                        
                          koji
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      Kotti CSRF in the local roles implementation
                    
                      
  High
                    
                
                      
                        CVE-2018-9856
                      
                      was published
                        for
                        
                          Kotti
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      JSNAPy allows unprivileged local users to alter files under the directory
                    
                      
  High
                    
                
                      
                        CVE-2018-0023
                      
                      was published
                        for
                        
                          jsnapy
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      Django-Anymail prone to a timing attack
                    
                      
  Critical
                    
                
                      
                        CVE-2018-6596
                      
                      was published
                        for
                        
                          django-anymail
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      tlslite-ng off-by-one error on mac checking
                    
                      
  High
                    
                
                      
                        CVE-2018-1000159
                      
                      was published
                        for
                        
                          tlslite-ng
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
                    
                      
  High
                    
                
                      
                        CVE-2018-1000164
                      
                      was published
                        for
                        
                          gunicorn
                        
                        (pip)
                      Jul 12, 2018 
                    
                  
                    
                      oslo.middleware Information Disclosure vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2017-2592
                      
                      was published
                        for
                        
                          oslo-middleware
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      django_make_app is vulnerable to Code Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2017-16764
                      
                      was published
                        for
                        
                          django_make_app
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      python-fedora vulnerable to an open redirect resulting in loss of CSRF protection
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-1002150
                      
                      was published
                        for
                        
                          python-fedora
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      Mercurial has Incorrect Permission Assignment for Critical Resource
                    
                      
  High
                    
                
                      
                        CVE-2017-9462
                      
                      was published
                        for
                        
                          mercurial
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      FedMsg not properly completing message validation
                    
                      
  High
                    
                
                      
                        CVE-2017-1000001
                      
                      was published
                        for
                        
                          FedMsg
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      django-epiceditor vulnerable to XSS in form field
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-6591
                      
                      was published
                        for
                        
                          django-epiceditor
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      cfscrape Improper Input Validation vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2017-7235
                      
                      was published
                        for
                        
                          cfscrape
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      Unsafe deserialization in MLAlchemy
                    
                      
  Critical
                    
                
                      
                        CVE-2017-16615
                      
                      was published
                        for
                        
                          MLAlchemy
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      Unsafe deserialization in owlmixin
                    
                      
  Critical
                    
                
                      
                        CVE-2017-16618
                      
                      was published
                        for
                        
                          owlmixin
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      pysaml2 Improper Authentication vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2017-1000433
                      
                      was published
                        for
                        
                          pysaml2
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
                    
                      Diffoscope may write to arbitrary locations due to an untrusted archive
                    
                      
  Critical
                    
                
                      
                        CVE-2017-0359
                      
                      was published
                        for
                        
                          diffoscope
                        
                        (pip)
                      Jul 13, 2018 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API