GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,529 advisories
Filter by severity
Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration...
High
Unreviewed
CVE-2026-30811
was published
Apr 13, 2026
Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers...
Moderate
Unreviewed
CVE-2026-21013
was published
Apr 13, 2026
Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability...
High
Unreviewed
CVE-2026-25203
was published
Apr 10, 2026
A container privilege escalation flaw was found in certain Ansible Automation Platform images....
Moderate
Unreviewed
CVE-2025-57847
was published
Apr 8, 2026
A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes...
Moderate
Unreviewed
CVE-2025-57851
was published
Apr 8, 2026
A container privilege escalation flaw was found in certain Web Terminal images. This issue stems...
Moderate
Unreviewed
CVE-2025-57853
was published
Apr 8, 2026
A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images...
Moderate
Unreviewed
CVE-2025-57854
was published
Apr 8, 2026
A container privilege escalation flaw was found in certain Red Hat Process Automation Manager...
Moderate
Unreviewed
CVE-2025-58713
was published
Apr 8, 2026
openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools
Moderate
CVE-2026-39398
was published
for
openclaw-claude-bridge
(npm)
Apr 8, 2026
Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows...
Moderate
Unreviewed
CVE-2025-7024
was published
Apr 3, 2026
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The...
High
Unreviewed
CVE-2026-21765
was published
Apr 2, 2026
Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool
Moderate
CVE-2026-34450
was published
for
anthropic
(pip)
Apr 1, 2026
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper...
Moderate
Unreviewed
CVE-2025-15615
was published
Mar 27, 2026
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper...
Moderate
Unreviewed
CVE-2026-32983
was published
Mar 27, 2026
In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with...
Moderate
Unreviewed
CVE-2026-0748
was published
Mar 27, 2026
The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation...
High
Unreviewed
CVE-2026-32680
was published
Mar 26, 2026
When a plugin is installed using the Arturia Software Center (MacOS), it also installs an...
High
Unreviewed
CVE-2026-24063
was published
Mar 18, 2026
Capgo CLI: symlink-following local secret writes enable arbitrary file overwrite + world-readable credentials (0600 missing)
High
GHSA-8mpm-q7mh-8fvh
was published
for
@capgo/cli
(npm)
Mar 18, 2026
OpenClaw session transcript files were created without forced user-only permissions
Moderate
CVE-2026-33572
was published
for
openclaw
(npm)
Mar 16, 2026
ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to...
Moderate
Unreviewed
CVE-2016-20029
was published
Mar 16, 2026
A container privilege escalation flaw was found in certain Fuse images. This issue stems from the...
Moderate
Unreviewed
CVE-2025-57849
was published
Mar 13, 2026
A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images...
Moderate
Unreviewed
CVE-2025-8766
was published
Mar 13, 2026
.NET Elevation of Privilege Vulnerability
High
CVE-2026-26131
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-26131 – .NET Elevation of Privilege Vulnerability
High
GHSA-387c-qmrw-59qv
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 10, 2026
•
withdrawn
Multiple i-フィルター products are configured with improper file access permission settings. Files may...
Moderate
Unreviewed
CVE-2026-28267
was published
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API