GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
97 advisories
Filter by severity
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
Low
GHSA-q6hv-wcjr-wp8h
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 26, 2025
The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address...
Low
Unreviewed
CVE-2025-11244
was published
Oct 25, 2025
A vulnerability was identified in fushengqian fuint up to...
Low
Unreviewed
CVE-2025-12623
was published
Nov 3, 2025
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Low
CVE-2024-30260
was published
for
undici
(npm)
Apr 4, 2024
A logic issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and...
Low
Unreviewed
CVE-2026-20656
was published
Feb 12, 2026
A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability...
Low
Unreviewed
CVE-2026-2974
was published
Feb 23, 2026
PSI Probe: Broken access control can lead to DoS
Low
CVE-2026-3269
was published
for
com.github.psi-probe:psi-probe-core
(Maven)
Feb 27, 2026
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
Low
CVE-2026-2733
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 19, 2026
OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Low
CVE-2026-31993
was published
for
openclaw
(npm)
Mar 2, 2026
A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the...
Low
Unreviewed
CVE-2026-4549
was published
Mar 22, 2026
A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer...
Low
Unreviewed
CVE-2026-4958
was published
Mar 27, 2026
Centrifugo's InsecureSkipTokenSignatureVerify flag silently disables JWT verification with no warning
Low
GHSA-q926-c743-49qj
was published
for
github.com/centrifugal/centrifugo
(Go)
Mar 13, 2026
Claude Code has Permission Deny Bypass Through Symbolic Links
Low
CVE-2026-25724
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
In affected versions of Octopus Server it was possible for a low privileged user to manipulate an...
Low
Unreviewed
CVE-2026-3237
was published
Mar 17, 2026
The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized...
Low
Unreviewed
CVE-2025-12958
was published
Jan 7, 2026
OpenClaw: Tlon settings empty-allowlist reconciliation bypassed intended revocation
Low
CVE-2026-35649
was published
for
openclaw
(npm)
Mar 26, 2026
A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected...
Low
Unreviewed
CVE-2026-7502
was published
May 1, 2026
A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is...
Low
Unreviewed
CVE-2026-7510
was published
May 1, 2026
A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function...
Low
Unreviewed
CVE-2026-7782
was published
May 5, 2026
A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file...
Low
Unreviewed
CVE-2026-8196
was published
May 9, 2026
A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the...
Low
Unreviewed
CVE-2026-8786
was published
May 18, 2026
A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the...
Low
Unreviewed
CVE-2026-9306
was published
May 26, 2026
A vulnerability was determined in AstrBotDevs AstrBot 4.23.6. Affected by this issue is the...
Low
Unreviewed
CVE-2026-10211
was published
Jun 1, 2026
A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the...
Low
Unreviewed
CVE-2026-11461
was published
Jun 8, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
Low
CVE-2026-46668
was published
for
github.com/authzed/spicedb
(Go)
May 21, 2026
ProTip!
Advisories are also available from the
GraphQL API