GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
203 advisories
Filter by severity
A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown...
Low
Unreviewed
CVE-2026-19337
was published
Aug 9, 2026
A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function...
Low
Unreviewed
CVE-2026-19246
was published
Aug 7, 2026
A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown...
Low
Unreviewed
CVE-2026-19040
was published
Aug 6, 2026
A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function...
Low
Unreviewed
CVE-2026-18856
was published
Aug 5, 2026
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function...
Low
Unreviewed
CVE-2026-18774
was published
Aug 4, 2026
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability...
Low
Unreviewed
CVE-2026-18775
was published
Aug 4, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function...
Low
Unreviewed
CVE-2026-17458
was published
Jul 26, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Low
CVE-2026-23603
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function...
Low
Unreviewed
CVE-2026-16223
was published
Jul 19, 2026
A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown...
Low
Unreviewed
CVE-2026-16222
was published
Jul 19, 2026
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function...
Low
Unreviewed
CVE-2026-16196
was published
Jul 19, 2026
A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function...
Low
Unreviewed
CVE-2026-16194
was published
Jul 19, 2026
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This...
Low
Unreviewed
CVE-2026-16124
was published
Jul 18, 2026
A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function...
Low
Unreviewed
CVE-2026-16074
was published
Jul 17, 2026
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A...
Low
Unreviewed
CVE-2026-62216
was published
Jul 17, 2026
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
Low
CVE-2026-58196
was published
for
github.com/stacklok/toolhive
(Go)
Jul 15, 2026
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway
Low
CVE-2026-54450
was published
for
github.com/stacklok/toolhive
(Go)
Jul 15, 2026
A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the...
Low
Unreviewed
CVE-2026-15750
was published
Jul 15, 2026
A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the...
Low
Unreviewed
CVE-2026-15668
was published
Jul 14, 2026
A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This...
Low
Unreviewed
CVE-2026-15628
was published
Jul 14, 2026
A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this...
Low
Unreviewed
CVE-2026-15624
was published
Jul 14, 2026
A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the...
Low
Unreviewed
CVE-2026-15620
was published
Jul 14, 2026
A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the...
Low
Unreviewed
CVE-2026-15619
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API