GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
75 advisories
Filter by severity
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of...
Moderate
Unreviewed
CVE-2026-44768
was published
Jul 14, 2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows...
Moderate
Unreviewed
CVE-2026-0232
was published
Apr 13, 2026
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain...
High
Unreviewed
CVE-2026-1784
was published
Jun 2, 2026
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
High
GHSA-jv2h-4p9v-wf5w
was published
for
ouroboros-ai
(pip)
Jun 19, 2026
Insufficient configuration management in the listed devices allows authenticated administrators...
Moderate
Unreviewed
CVE-2026-0418
was published
Jun 9, 2026
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1...
High
Unreviewed
CVE-2026-6973
was published
May 7, 2026
Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action`
Critical
CVE-2026-45087
was published
for
github.com/hahwul/dalfox/v2
(Go)
May 12, 2026
Taguette password reset link poisoning
High
CVE-2025-62527
was published
for
taguette
(pip)
Oct 20, 2025
Netavark Has Possible DNS Resolve Confusion
Low
CVE-2025-8283
was published
for
netavark
(Rust)
Jul 28, 2025
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service...
High
Unreviewed
CVE-2019-25716
was published
Jun 2, 2026
OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Moderate
CVE-2026-44992
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Workspace .env could inject OpenClaw runtime-control variables
Moderate
CVE-2026-43531
was published
for
openclaw
(npm)
Apr 17, 2026
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows...
Moderate
Unreviewed
CVE-2026-30817
was published
Apr 8, 2026
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0...
Moderate
Unreviewed
CVE-2026-30816
was published
Apr 8, 2026
OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code
High
CVE-2026-41336
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Workspace `.env` can override the bundled plugin trust root
High
CVE-2026-41396
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw Has Incomplete Fix for CVE-2026-4039: CLI Backend Environment Variable Injection via Workspace Config
High
CVE-2026-41384
was published
for
openclaw
(npm)
Apr 7, 2026
Spring Cloud Gateway's SSL bundle configuration silently bypassed
High
CVE-2026-22750
was published
for
org.springframework.cloud:spring-cloud-gateway
(Maven)
Apr 10, 2026
OpenClaw has Inconsistent Host Exec Environment Override Sanitization
High
CVE-2026-35650
was published
for
openclaw
(npm)
Mar 26, 2026
Local privilege escalation due to improper handling of environment variables. The following...
High
Unreviewed
CVE-2026-33092
was published
Apr 10, 2026
OpenClaw's config env vars allowed startup env injection into service runtime
Moderate
CVE-2026-22177
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
Low
CVE-2026-32058
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)
High
CVE-2026-32056
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE)
High
CVE-2026-32003
was published
for
openclaw
(npm)
Mar 3, 2026
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process...
High
Unreviewed
CVE-2024-1488
was published
Feb 15, 2024
ProTip!
Advisories are also available from the
GraphQL API