GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,538
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34 advisories
Filter by severity
social-auth-app-django affected by Improper Handling of Case Sensitivity
Moderate
CVE-2024-32879
was published
for
social-auth-app-django
(pip)
Apr 24, 2024
VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext
Low
CVE-2025-32021
was published
for
weblate
(pip)
Apr 15, 2025
Weblate lacks rate limiting when verifying second factor
Moderate
CVE-2025-47951
was published
for
weblate
(pip)
Jun 16, 2025
Weblate exposes personal IP address via e-mail
Low
CVE-2025-49134
was published
for
weblate
(pip)
Jun 16, 2025
Weblate has a long session expiry when verifying second factor
Low
CVE-2025-58352
was published
for
Weblate
(pip)
Sep 4, 2025
Python Social Auth - Django has unsafe account association
Moderate
CVE-2025-61783
was published
for
social-auth-app-django
(pip)
Oct 9, 2025
Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Moderate
CVE-2025-64716
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 30, 2025
Weblate has an arbitrary file read via symbolic links
High
CVE-2025-68279
was published
for
Weblate
(pip)
Dec 18, 2025
Weblate command-line client susceptible to SSL verification skip
Low
CVE-2026-22250
was published
for
wlc
(pip)
Jan 12, 2026
Weblate wlc has insecure API key configuration
Moderate
CVE-2026-22251
was published
for
wlc
(pip)
Jan 12, 2026
Weblate leaks information via screenshots
Low
CVE-2026-21889
was published
for
weblate
(pip)
Jan 14, 2026
Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
High
CVE-2026-23535
was published
for
wlc
(pip)
Jan 16, 2026
Weblate is vulnerable to RCE through Git config file overwrite
Critical
CVE-2025-68398
was published
for
Weblate
(pip)
Dec 18, 2025
Weblate has an argument injection in management console
Moderate
CVE-2026-24126
was published
for
Weblate
(pip)
Feb 17, 2026
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Moderate
CVE-2026-27457
was published
for
weblate
(pip)
Feb 26, 2026
Weblate: Improper access control for pending tasks in API
Low
CVE-2026-33212
was published
for
weblate
(pip)
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
Moderate
CVE-2026-33440
was published
for
weblate
(pip)
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
Moderate
CVE-2026-34244
was published
for
weblate
(pip)
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
Moderate
CVE-2026-40256
was published
for
weblate
(pip)
Apr 16, 2026
Weblate Doesn't Invalidate API Token on Password Change
Moderate
CVE-2026-41519
was published
for
weblate
(pip)
Apr 30, 2026
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
Moderate
CVE-2026-41654
was published
for
weblate
(pip)
Apr 30, 2026
Weblate vulnerable to XSS via crafted Markdown
Moderate
CVE-2026-44264
was published
for
weblate
(pip)
May 7, 2026
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
Moderate
CVE-2026-44263
was published
for
weblate
(pip)
May 7, 2026
wlc: print_html outputs API data without HTML escaping
Moderate
CVE-2026-42150
was published
for
wlc
(pip)
Apr 24, 2026
Weblate has a Server-Side Request Forgery issue
Moderate
CVE-2025-66407
was published
for
Weblate
(pip)
May 26, 2026
ProTip!
Advisories are also available from the
GraphQL API