GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28 advisories
Filter by severity
Malicious package may avoid detection in python auditing
Moderate
CVE-2020-5252
was published
for
safety
(pip)
Mar 24, 2020
A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC)...
Moderate
Unreviewed
CVE-2022-20744
was published
May 4, 2022
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to...
Moderate
Unreviewed
CVE-2017-0887
was published
May 13, 2022
A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS...
Moderate
Unreviewed
CVE-2022-24400
was published
Oct 19, 2023
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to...
Moderate
Unreviewed
CVE-2023-46686
was published
Dec 19, 2023
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Moderate
CVE-2024-21510
was published
for
sinatra
(RubyGems)
Nov 1, 2024
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient
Verification of Data...
Moderate
Unreviewed
CVE-2024-47254
was published
Nov 5, 2024
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to...
Moderate
Unreviewed
CVE-2024-45654
was published
Jan 19, 2025
By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals...
Moderate
Unreviewed
CVE-2024-9310
was published
Jan 22, 2025
Duplicate Advisory: Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
GHSA-hw34-rqc5-h2gm
was published
for
picklescan
(pip)
Mar 3, 2025
•
withdrawn
github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Moderate
CVE-2025-47909
was published
for
github.com/gorilla/csrf
(Go)
Aug 29, 2025
The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all...
Moderate
Unreviewed
CVE-2025-11271
was published
Nov 6, 2025
Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF)...
Moderate
Unreviewed
CVE-2025-65328
was published
Jan 5, 2026
OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
Moderate
CVE-2026-32057
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions
Moderate
CVE-2026-32029
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Zalouser allowlist authorization matched mutable group names by default
Moderate
GHSA-f5mf-3r52-r83w
was published
for
openclaw
(npm)
Mar 13, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
Moderate
CVE-2026-29794
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
Moderate
GHSA-xh9j-mpc9-2m9p
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata
Moderate
GHSA-rcx4-77x4-hjx5
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the...
Moderate
Unreviewed
CVE-2019-25544
was published
Mar 21, 2026
ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to...
Moderate
Unreviewed
CVE-2019-25594
was published
Mar 22, 2026
Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash...
Moderate
Unreviewed
CVE-2019-25621
was published
Mar 24, 2026
OpenClaw: Synology Chat reply delivery could be rebound through username-based user resolution.
Moderate
CVE-2026-35670
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw's Conflicting Tool Identity Hints Bypass Dangerous-Tool Prompting
Moderate
CVE-2026-35655
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode...
Moderate
Unreviewed
CVE-2026-32975
was published
Mar 29, 2026
ProTip!
Advisories are also available from the
GraphQL API