Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

10 advisories

Loading
Keycloak Account Resources user lookup contains broken access control Moderate
CVE-2026-37981 was published for org.keycloak:keycloak-services (Maven) May 19, 2026
coffeemakr Credited to coffeemakr
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions Moderate
CVE-2026-40690 was published for apache-airflow (pip) Apr 24, 2026
OpenClaw: Agent gateway config mutations could change protected operator settings Moderate
GHSA-7jm2-g593-4qrc was published for openclaw (npm) Apr 25, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
Improper authorization in zenml Moderate
CVE-2024-2035 was published for zenml (pip) Jun 6, 2024
Kimai API returns timesheet entries a user should not be authorized to view Moderate
CVE-2024-29200 was published for kimai/kimai (Composer) Mar 29, 2024
AstroGD Credited to AstroGD
Withdrawn Advisory: Lunary information disclosure vulnerability Moderate
CVE-2024-6867 was published for lunary (npm) Sep 13, 2024 withdrawn
hughcrt Credited to hughcrt
lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management Moderate
CVE-2024-5389 was published for lunary (npm) Jun 10, 2024 withdrawn
usememos/memos has Insufficient Granularity of Access Control Moderate
CVE-2022-4801 was published for github.com/usememos/memos (Go) Dec 28, 2022
usememos/memos has Insufficient Granularity of Access Control Moderate
CVE-2022-4813 was published for github.com/usememos/memos (Go) Dec 28, 2022
ProTip! Advisories are also available from the GraphQL API