GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
58
GitHub Actions
50
Go
3,788
Maven
5,000+
npm
5,000+
NuGet
938
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,349
Swift
54
Unreviewed advisories
All unreviewed
5,000+
224 advisories
Filter by severity
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API...
Critical
Unreviewed
CVE-2026-30805
was published
May 12, 2026
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could...
High
Unreviewed
CVE-2026-6866
was published
May 12, 2026
Affected devices do not properly restrict access to the web browser via the Control Panel when no...
High
Unreviewed
CVE-2026-27662
was published
May 12, 2026
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
High
CVE-2026-44338
was published
for
PraisonAI
(pip)
May 11, 2026
SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)
Critical
CVE-2026-44588
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
May 8, 2026
SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE
Critical
CVE-2026-44670
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
May 8, 2026
OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox...
Critical
Unreviewed
CVE-2026-43581
was published
May 6, 2026
Duplicate Advisory: OpenClaw: Feishu webhook and card-action validation now fail closed
Critical
GHSA-cjg8-85gj-v9q2
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only....
Low
Unreviewed
CVE-2025-31974
was published
May 6, 2026
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2...
Critical
Unreviewed
CVE-2026-39920
was published
Apr 24, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
High
CVE-2026-41432
was published
for
github.com/QuantumNous/new-api
(Go)
Apr 24, 2026
P4 Server versions prior to 2026.1 are configured with insecure default settings that, when...
High
Unreviewed
CVE-2026-6043
was published
Apr 24, 2026
Gitea has insecure default SSH settings
Moderate
GHSA-3m6q-h5gj-7mrw
was published
for
code.gitea.io/gitea
(Go)
Apr 22, 2026
engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection
High
GHSA-2r2p-4cgf-hv7h
was published
for
engramx
(npm)
Apr 22, 2026
Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC...
High
Unreviewed
CVE-2026-32965
was published
Apr 20, 2026
OpenClaw: Feishu webhook and card-action validation now fail closed
Critical
CVE-2026-44109
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Browser SSRF policy default allowed private-network navigation
Moderate
CVE-2026-43527
was published
for
openclaw
(npm)
Apr 17, 2026
paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
Critical
CVE-2026-41679
was published
for
@paperclipai/server
(npm)
Apr 10, 2026
OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default...
Critical
Unreviewed
CVE-2026-28205
was published
Apr 9, 2026
openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools
Moderate
CVE-2026-39398
was published
for
openclaw-claude-bridge
(npm)
Apr 8, 2026
Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist
Critical
CVE-2026-31818
was published
for
@budibase/backend-core
(npm)
Apr 3, 2026
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
High
CVE-2026-34780
was published
for
electron
(npm)
Apr 3, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
High
CVE-2026-34742
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Apr 1, 2026
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an...
High
Unreviewed
CVE-2026-24148
was published
Mar 31, 2026
Duplicate Advisory: OpenClaw has an improper sandbox configuration vulnerability
Moderate
GHSA-q94v-v6m9-jhq9
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API