GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
36 advisories
Filter by severity
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference...
High
Unreviewed
CVE-2026-29036
was published
Aug 12, 2026
File Browser: Colliding username normalization gives two users the same home directory
High
CVE-2026-62685
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock...
High
Unreviewed
CVE-2026-62190
was published
Jul 14, 2026
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions...
High
Unreviewed
CVE-2026-13372
was published
Jun 26, 2026
Use of an incorrectly resolved name or reference in the pinget backend
in Devolutions UniGetUI...
High
Unreviewed
CVE-2026-10696
was published
Jun 17, 2026
Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
High
GHSA-83hf-93m4-rgwq
was published
for
hickory-recursor
(Rust)
Apr 30, 2026
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
High
CVE-2026-40912
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
OpenClaw's system.run allowlist can be bypassed through an unregistered time dispatch wrapper
High
CVE-2026-35666
was published
for
openclaw
(npm)
Mar 26, 2026
opennextjs-cloudflare has SSRF vulnerability via /cdn-cgi/ path normalization bypass
High
CVE-2026-3125
was published
for
@opennextjs/cloudflare
(npm)
Mar 5, 2026
File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
High
CVE-2026-25890
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Feb 10, 2026
An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8...
High
Unreviewed
CVE-2025-65474
was published
Dec 11, 2025
Hono's flaw in URL path parsing could cause path confusion
High
CVE-2025-58362
was published
for
hono
(npm)
Sep 3, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-48136
was published
May 16, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-30870
was published
Apr 1, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-30849
was published
Apr 1, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-53739
was published
Nov 30, 2024
The Qi Addons For Elementor plugin for WordPress is vulnerable to Remote File Inclusion in all...
High
Unreviewed
CVE-2024-4887
was published
Jun 7, 2024
In the Linux kernel, the following vulnerability has been resolved:
IB/mlx5: Fix initializing CQ...
High
Unreviewed
CVE-2021-47261
was published
May 21, 2024
Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2023-42125
was published
May 3, 2024
Directus has MySQL accent insensitive email matching
High
CVE-2024-27295
was published
for
directus
(npm)
Mar 1, 2024
Docassemble unauthorized access through URL manipulation
High
CVE-2024-27292
was published
for
docassemble.base
(pip)
Feb 29, 2024
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
High
CVE-2023-34092
was published
for
vite
(npm)
Jun 6, 2023
Opencontainers runc Incorrect Authorization vulnerability
High
CVE-2023-27561
was published
for
github.com/opencontainers/runc
(Go)
Mar 3, 2023
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when...
High
Unreviewed
CVE-2022-27778
was published
Jun 3, 2022
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR)...
High
Unreviewed
CVE-2021-37214
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API