GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
22 advisories
Filter by severity
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of...
Moderate
Unreviewed
CVE-2026-44768
was published
Jul 14, 2026
Insufficient configuration management in the listed devices allows authenticated administrators...
Moderate
Unreviewed
CVE-2026-0418
was published
Jun 9, 2026
OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Moderate
CVE-2026-44992
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Workspace .env could inject OpenClaw runtime-control variables
Moderate
CVE-2026-43531
was published
for
openclaw
(npm)
Apr 17, 2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows...
Moderate
Unreviewed
CVE-2026-0232
was published
Apr 13, 2026
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows...
Moderate
Unreviewed
CVE-2026-30817
was published
Apr 8, 2026
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0...
Moderate
Unreviewed
CVE-2026-30816
was published
Apr 8, 2026
OpenClaw's `system.run` env override filtering allowed dangerous helper-command pivots
Moderate
GHSA-j425-whc4-4jgc
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw shell-env fallback trusted startup env and could execute attacker-influenced login-shell paths
Moderate
GHSA-5h2c-8v84-qpvr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's config env vars allowed startup env injection into service runtime
Moderate
CVE-2026-22177
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's non-default safeBins sort configuration can bypass intended allowlist approval constraints
Moderate
CVE-2026-22169
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)
Moderate
CVE-2026-4039
was published
for
openclaw
(npm)
Feb 27, 2026
The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a...
Moderate
Unreviewed
CVE-2025-13091
was published
Feb 19, 2026
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to...
Moderate
Unreviewed
CVE-2026-0495
was published
Jan 13, 2026
Post-authenticated external control of system web interface configuration setting vulnerability...
Moderate
Unreviewed
CVE-2025-41452
was published
Aug 22, 2025
Unauthenticated attackers can send configuration settings to device and possible perform physical...
Moderate
Unreviewed
CVE-2025-30512
was published
Apr 16, 2025
An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60...
Moderate
Unreviewed
CVE-2025-27253
was published
Mar 10, 2025
github.com/gitpod-io/gitpod vulnerable to Cookie Tossing
Moderate
CVE-2024-21583
was published
for
github.com/gitpod-io/gitpod
(Go)
Jul 19, 2024
Micronaut management endpoints vulnerable to drive-by localhost attack
Moderate
CVE-2024-23639
was published
for
io.micronaut:micronaut-http-server
(Maven)
Feb 9, 2024
Unauthorized startup vulnerability of background apps. Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-46764
was published
Nov 8, 2023
mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed,...
Moderate
Unreviewed
CVE-2023-43323
was published
Sep 28, 2023
in-toto vulnerable to Configuration Read From Local Directory
Moderate
CVE-2023-32076
was published
for
in-toto
(pip)
May 11, 2023
ProTip!
Advisories are also available from the
GraphQL API