GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
15,586 advisories
Filter by severity
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that...
Low
Unreviewed
CVE-2024-23573
was published
Jul 17, 2026
Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042...
Low
Unreviewed
CVE-2024-32389
was published
Jul 16, 2026
A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This...
Low
Unreviewed
CVE-2026-16008
was published
Jul 17, 2026
A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an...
Low
Unreviewed
CVE-2026-16009
was published
Jul 17, 2026
grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the...
Low
Unreviewed
CVE-2026-62236
was published
Jul 17, 2026
Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the...
Low
Unreviewed
CVE-2026-62235
was published
Jul 17, 2026
OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the...
Low
Unreviewed
CVE-2026-62221
was published
Jul 17, 2026
OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the...
Low
Unreviewed
CVE-2026-62224
was published
Jul 17, 2026
OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command...
Low
Unreviewed
CVE-2026-62225
was published
Jul 17, 2026
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A...
Low
Unreviewed
CVE-2026-62216
was published
Jul 17, 2026
Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM...
Low
Unreviewed
CVE-2026-15997
was published
Jul 17, 2026
ZPan Uses Hard-Coded Password
Low
CVE-2025-7453
was published
for
github.com/saltbo/zpan
(Go)
Jul 11, 2025
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor...
Low
Unreviewed
CVE-2026-47087
was published
Jul 16, 2026
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an...
Low
Unreviewed
CVE-2026-47081
was published
Jul 16, 2026
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in...
Low
Unreviewed
CVE-2026-47088
was published
Jul 16, 2026
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can...
Low
Unreviewed
CVE-2026-47086
was published
Jul 16, 2026
nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof
Low
CVE-2026-54542
was published
for
nimiq-primitives
(Rust)
Jul 16, 2026
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys
Low
CVE-2026-54541
was published
for
nimiq-primitives
(Rust)
Jul 16, 2026
Keycloak: Information disclosure due to user profile permission bypass
Low
CVE-2026-9088
was published
for
org.keycloak:keycloak-services
(Maven)
Jun 5, 2026
The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX...
Low
Unreviewed
CVE-2026-12906
was published
Jul 16, 2026
The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its...
Low
Unreviewed
CVE-2026-12907
was published
Jul 16, 2026
CVE-2026-40958
is a input validation error in Secure Access clients prior to 14.55. Attackers...
Low
Unreviewed
CVE-2026-40958
was published
Jul 15, 2026
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a...
Low
Unreviewed
CVE-2026-35141
was published
Jul 16, 2026
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie...
Low
Unreviewed
CVE-2026-35140
was published
Jul 16, 2026
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability....
Low
Unreviewed
CVE-2026-35145
was published
Jul 16, 2026
ProTip!
Advisories are also available from the
GraphQL API