GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
275 advisories
Filter by severity
OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass
Low
CVE-2026-41402
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection
Moderate
CVE-2026-41337
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
High
CVE-2026-41395
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing...
Critical
Unreviewed
CVE-2026-32987
was published
Mar 29, 2026
mpp has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-fxc9-7j2w-vx54
was published
for
mpp
(Rust)
Mar 29, 2026
mppx has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-8x4m-qw58-3pcx
was published
for
mppx
(npm)
Mar 29, 2026
mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality
High
CVE-2026-34209
was published
for
mppx
(npm)
Mar 29, 2026
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth...
Moderate
Unreviewed
CVE-2026-27855
was published
Mar 27, 2026
OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
High
CVE-2026-35618
was published
for
openclaw
(npm)
Mar 26, 2026
Duplicate Advisory: OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse
Moderate
GHSA-3r78-rqg8-95gg
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing
Moderate
GHSA-866c-wwm5-4rj7
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote...
High
Unreviewed
CVE-2026-20999
was published
Mar 16, 2026
Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120...
High
Unreviewed
CVE-2025-13777
was published
Mar 13, 2026
Authentication Bypass by Capture-replay, Use of Password Hash With Insufficient Computational...
Critical
Unreviewed
CVE-2026-30789
was published
Mar 5, 2026
OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing
Moderate
CVE-2026-28449
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identity
Low
GHSA-gcj7-r3hg-m7w6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse
Moderate
CVE-2026-32053
was published
for
openclaw
(npm)
Mar 3, 2026
OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
High
CVE-2026-28787
was published
for
@oneuptime/common
(npm)
Mar 2, 2026
Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to...
Critical
Unreviewed
CVE-2025-67135
was published
Feb 12, 2026
Crafted zones can lead to increased incoming network traffic.
Moderate
Unreviewed
CVE-2026-24027
was published
Feb 9, 2026
Crafted delegations or IP fragments can poison cached delegations in Recursor.
High
Unreviewed
CVE-2025-59023
was published
Feb 9, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication
Moderate
CVE-2025-68671
was published
for
github.com/treeverse/lakefs
(Go)
Jan 15, 2026
D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz...
Critical
Unreviewed
CVE-2025-65552
was published
Jan 12, 2026
D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm...
Moderate
Unreviewed
CVE-2025-65553
was published
Jan 12, 2026
A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected...
Moderate
Unreviewed
CVE-2025-40807
was published
Dec 9, 2025
ProTip!
Advisories are also available from the
GraphQL API