GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
3,940 advisories
Filter by severity
Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon...
High
Unreviewed
CVE-2026-26418
was published
Mar 5, 2026
A broken access control vulnerability in the password reset functionality of Tata Consultancy...
High
Unreviewed
CVE-2026-26417
was published
Mar 5, 2026
Gokapi has privilege escalation via incomplete API-key permission revocation on user rank demotion
Moderate
CVE-2026-29061
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Gokapi has privilege escalation with auth token
Moderate
CVE-2026-29060
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Gokapi has Data Leak in Upload Status Stream
Moderate
CVE-2026-28682
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5...
High
Unreviewed
CVE-2026-25702
was published
Mar 5, 2026
File Browser's TUS Delete Endpoint Bypasses Delete Permission Check
Critical
CVE-2026-29188
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 4, 2026
Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote...
High
Unreviewed
CVE-2026-3543
was published
Mar 4, 2026
Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a...
High
Unreviewed
CVE-2026-3542
was published
Mar 4, 2026
Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote...
High
Unreviewed
CVE-2026-3541
was published
Mar 4, 2026
OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace images
Moderate
GHSA-q6qf-4p5j-r25g
was published
for
openclaw
(npm)
Mar 4, 2026
A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco...
Moderate
Unreviewed
CVE-2026-20073
was published
Mar 4, 2026
A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat...
Moderate
Unreviewed
CVE-2026-20007
was published
Mar 4, 2026
OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch
Moderate
GHSA-534w-2vm4-89xr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch
Moderate
GHSA-gw85-xp4q-5gp9
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Experimental apply_patch may bypass workspace-only checks in opt-in sandbox mounts (off by default)
Moderate
GHSA-h9xm-j4qg-fvpg
was published
for
openclaw
(npm)
Mar 3, 2026
Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS...
Moderate
Unreviewed
CVE-2024-55025
was published
Mar 3, 2026
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web...
Moderate
Unreviewed
CVE-2024-55019
was published
Mar 3, 2026
OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode
Moderate
GHSA-ccg8-46r6-9qgj
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runs
High
GHSA-9f72-qcpw-2hxc
was published
for
openclaw
(npm)
Mar 3, 2026
Temporary path handling could write outside OpenClaw temp boundary
Moderate
GHSA-33hm-cq8r-wc49
was published
for
openclaw
(npm)
Mar 3, 2026
Rancher cloud credentials can be used through proxy API by users without access
Critical
CVE-2021-25320
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
OpenClaw has a sandbox network isolation bypass via docker.network=container:<id>
Moderate
GHSA-ww6v-v748-x7g9
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns
Moderate
GHSA-p7gr-f84w-hqg5
was published
for
openclaw
(npm)
Mar 2, 2026
OliveTin has Unauthenticated Action Termination via KillAction When Guests Must Login
High
CVE-2026-28790
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API