GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,575
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,523
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,072 advisories
Filter by severity
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled...
High
Unreviewed
CVE-2026-47937
was published
Jun 9, 2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are...
High
Unreviewed
CVE-2026-44682
was published
Jun 3, 2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are...
High
Unreviewed
CVE-2026-50033
was published
Jun 3, 2026
Local privilege escalation due to EXE hijacking vulnerability. The following products are...
High
Unreviewed
CVE-2026-44609
was published
Jun 3, 2026
A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to...
High
Unreviewed
CVE-2026-36574
was published
Jun 3, 2026
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for...
High
Unreviewed
CVE-2023-52945
was published
May 27, 2026
A local user with low privileges may be able to influence the behavior of a privileged system...
High
Unreviewed
CVE-2025-41670
was published
May 27, 2026
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network ...
Low
Unreviewed
CVE-2025-14575
was published
May 19, 2026
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability...
High
Unreviewed
CVE-2026-47092
was published
May 18, 2026
Docker: `PUT /containers/{id}/archive` executes container binary on the host
High
CVE-2026-41567
was published
for
github.com/docker/docker
(Go)
May 18, 2026
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve...
High
Unreviewed
CVE-2024-36333
was published
May 15, 2026
Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged...
High
Unreviewed
CVE-2025-62628
was published
May 14, 2026
Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic...
High
Unreviewed
CVE-2026-44612
was published
May 13, 2026
Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and...
Moderate
Unreviewed
CVE-2024-47091
was published
May 13, 2026
Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3...
Moderate
Unreviewed
CVE-2025-36515
was published
May 12, 2026
Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers...
Moderate
Unreviewed
CVE-2026-20772
was published
May 12, 2026
Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version...
Moderate
Unreviewed
CVE-2025-35969
was published
May 12, 2026
Duplicate Advisory: OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
High
GHSA-xpr6-2hgm-4wwp
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control...
Critical
Unreviewed
CVE-2025-69599
was published
May 8, 2026
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since...
Moderate
Unreviewed
CVE-2026-44406
was published
May 7, 2026
There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview....
Moderate
Unreviewed
CVE-2026-40004
was published
May 7, 2026
Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows...
High
Unreviewed
CVE-2026-21661
was published
May 6, 2026
Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using...
High
Unreviewed
CVE-2026-6788
was published
May 6, 2026
OpenClaw: Workspace dotenv files cannot override connector endpoint hosts
Moderate
CVE-2026-45003
was published
for
openclaw
(npm)
May 4, 2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are...
Moderate
Unreviewed
CVE-2026-25852
was published
Apr 29, 2026
ProTip!
Advisories are also available from the
GraphQL API