GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
75 advisories
Filter by severity
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of...
Moderate
Unreviewed
CVE-2026-44768
was published
Jul 14, 2026
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
High
GHSA-jv2h-4p9v-wf5w
was published
for
ouroboros-ai
(pip)
Jun 19, 2026
Insufficient configuration management in the listed devices allows authenticated administrators...
Moderate
Unreviewed
CVE-2026-0418
was published
Jun 9, 2026
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain...
High
Unreviewed
CVE-2026-1784
was published
Jun 2, 2026
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service...
High
Unreviewed
CVE-2019-25716
was published
Jun 2, 2026
Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action`
Critical
CVE-2026-45087
was published
for
github.com/hahwul/dalfox/v2
(Go)
May 12, 2026
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1...
High
Unreviewed
CVE-2026-6973
was published
May 7, 2026
OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Moderate
CVE-2026-44992
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Workspace .env could inject OpenClaw runtime-control variables
Moderate
CVE-2026-43531
was published
for
openclaw
(npm)
Apr 17, 2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows...
Moderate
Unreviewed
CVE-2026-0232
was published
Apr 13, 2026
Local privilege escalation due to improper handling of environment variables. The following...
High
Unreviewed
CVE-2026-33092
was published
Apr 10, 2026
Spring Cloud Gateway's SSL bundle configuration silently bypassed
High
CVE-2026-22750
was published
for
org.springframework.cloud:spring-cloud-gateway
(Maven)
Apr 10, 2026
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows...
Moderate
Unreviewed
CVE-2026-30817
was published
Apr 8, 2026
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0...
Moderate
Unreviewed
CVE-2026-30816
was published
Apr 8, 2026
OpenClaw Has Incomplete Fix for CVE-2026-4039: CLI Backend Environment Variable Injection via Workspace Config
High
CVE-2026-41384
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Workspace `.env` can override the bundled plugin trust root
High
CVE-2026-41396
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code
High
CVE-2026-41336
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw has Inconsistent Host Exec Environment Override Sanitization
High
CVE-2026-35650
was published
for
openclaw
(npm)
Mar 26, 2026
RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
Critical
CVE-2026-30960
was published
for
rssn
(Rust)
Mar 10, 2026
OpenClaw's `system.run` env override filtering allowed dangerous helper-command pivots
Moderate
GHSA-j425-whc4-4jgc
was published
for
openclaw
(npm)
Mar 9, 2026
Dell PowerScale OneFS, versions 9.10.0.0 through 9.10.1.5 and versions 9.11.0.0 through 9.12.0.1,...
Low
Unreviewed
CVE-2026-21422
was published
Mar 4, 2026
OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)
High
CVE-2026-32056
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commands
High
GHSA-w9cg-v44m-4qv8
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw shell-env fallback trusted startup env and could execute attacker-influenced login-shell paths
Moderate
GHSA-5h2c-8v84-qpvr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's config env vars allowed startup env injection into service runtime
Moderate
CVE-2026-22177
was published
for
openclaw
(npm)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API