GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
75 advisories
Filter by severity
Liferay Portal has External Control of System or Configuration Settings
Low
CVE-2025-43792
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Sep 15, 2025
An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60...
Moderate
Unreviewed
CVE-2025-27253
was published
Mar 10, 2025
ingress-nginx controller - configuration injection via unsanitized mirror annotations
High
CVE-2025-1098
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
High
CVE-2025-1097
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database...
High
Unreviewed
CVE-2024-10979
was published
Nov 14, 2024
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality...
Critical
Unreviewed
CVE-2024-39788
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality...
Critical
Unreviewed
CVE-2024-39790
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd...
Critical
Unreviewed
CVE-2024-39795
was published
Jan 14, 2025
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup()...
Critical
Unreviewed
CVE-2024-39798
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality...
Critical
Unreviewed
CVE-2024-39789
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd...
Critical
Unreviewed
CVE-2024-39794
was published
Jan 14, 2025
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup()...
Critical
Unreviewed
CVE-2024-39799
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd...
Critical
Unreviewed
CVE-2024-39793
was published
Jan 14, 2025
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup()...
Critical
Unreviewed
CVE-2024-39800
was published
Jan 14, 2025
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to...
Moderate
Unreviewed
CVE-2026-0495
was published
Jan 13, 2026
ingress-nginx controller - configuration injection via unsanitized auth-url annotation
High
CVE-2025-24514
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a...
Moderate
Unreviewed
CVE-2025-13091
was published
Feb 19, 2026
eBay API MCP Server Affected by Environment Variable Injection
High
CVE-2026-27203
was published
for
ebay-mcp
(npm)
Feb 19, 2026
OpenClaw shell-env fallback trusted startup env and could execute attacker-influenced login-shell paths
Moderate
GHSA-5h2c-8v84-qpvr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commands
High
GHSA-w9cg-v44m-4qv8
was published
for
openclaw
(npm)
Mar 3, 2026
Dell PowerScale OneFS, versions 9.10.0.0 through 9.10.1.5 and versions 9.11.0.0 through 9.12.0.1,...
Low
Unreviewed
CVE-2026-21422
was published
Mar 4, 2026
OpenClaw's `system.run` env override filtering allowed dangerous helper-command pivots
Moderate
GHSA-j425-whc4-4jgc
was published
for
openclaw
(npm)
Mar 9, 2026
RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
Critical
CVE-2026-30960
was published
for
rssn
(Rust)
Mar 10, 2026
OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)
Moderate
CVE-2026-4039
was published
for
openclaw
(npm)
Feb 27, 2026
OpenClaw's non-default safeBins sort configuration can bypass intended allowlist approval constraints
Moderate
CVE-2026-22169
was published
for
openclaw
(npm)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API