GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,413
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,656
Pub
13
RubyGems
1,027
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
354 advisories
Filter by severity
changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering
Critical
CVE-2026-35490
was published
for
changedetection.io
(pip)
Apr 6, 2026
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges...
Critical
Unreviewed
CVE-2026-32213
was published
Apr 3, 2026
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-33105
was published
Apr 3, 2026
OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation
Critical
GHSA-g5cg-8x5w-7jpm
was published
for
openclaw
(npm)
Apr 2, 2026
PraisonAI Has Authentication Bypass via OAuthManager.validate_token()
Critical
CVE-2026-34953
was published
for
praisonai
(pip)
Apr 1, 2026
OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation
Critical
CVE-2026-33579
was published
for
openclaw
(npm)
Mar 31, 2026
parse-server has cloud function validator bypass via prototype chain traversal
Critical
CVE-2026-34532
was published
for
parse-server
(npm)
Mar 31, 2026
Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
Critical
GHSA-hh43-q692-2xmq
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf...
Critical
Unreviewed
CVE-2026-32915
was published
Mar 29, 2026
Duplicate Advisory: OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity
Critical
GHSA-rwwx-25m7-ww73
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
Critical
GHSA-fqw4-mph7-2vr8
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
Critical
GHSA-9hjh-fr4f-gxc4
was published
for
openclaw
(npm)
Mar 27, 2026
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
Critical
CVE-2026-32767
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter
Critical
CVE-2026-30965
was published
for
parse-server
(npm)
Mar 11, 2026
The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor...
Critical
Unreviewed
CVE-2026-29127
was published
Mar 5, 2026
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Critical
CVE-2022-31247
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in Gateway
Critical
CVE-2026-28466
was published
for
openclaw
(npm)
Mar 2, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints
Critical
CVE-2026-27112
was published
for
github.com/akuity/kargo
(Go)
Feb 19, 2026
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC,...
Critical
Unreviewed
CVE-2025-66719
was published
Jan 23, 2026
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function
Critical
CVE-2026-22822
was published
for
github.com/external-secrets/external-secrets
(Go)
Jan 20, 2026
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root...
Critical
Unreviewed
CVE-2025-13184
was published
Dec 10, 2025
The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to...
Critical
Unreviewed
CVE-2024-5539
was published
Nov 27, 2025
Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and...
Critical
Unreviewed
CVE-2025-55469
was published
Nov 26, 2025
lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper...
Critical
Unreviewed
CVE-2025-9803
was published
Nov 25, 2025
Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows...
Critical
Unreviewed
CVE-2025-41346
was published
Nov 18, 2025
ProTip!
Advisories are also available from the
GraphQL API