Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,473 advisories

Loading
OpenClaw: Hook mapping templates could bypass hook session-key opt-in Moderate
CVE-2026-45002 was published for openclaw (npm) Apr 25, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application Moderate Unreviewed
CVE-2025-15626 was published Apr 27, 2026
Duplicate Advisory: OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections Moderate
GHSA-f5fm-9jmp-c88r was published for openclaw (npm) Apr 28, 2026 withdrawn
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure Moderate
CVE-2026-42227 was published for n8n (npm) Apr 29, 2026
nkoorty Credited to nkoorty and jjjutla jjjutla jjjutla
Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic High
CVE-2026-42609 was published for getgrav/grav (Composer) May 5, 2026
AnhNg1410 Credited to AnhNg1410
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows... Moderate Unreviewed
CVE-2026-41950 was published May 5, 2026
AVideo: IDOR in PayPalYPT Plugin Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements Moderate
CVE-2026-43883 was published for wwbn/avideo (Composer) May 5, 2026
offset Credited to offset
Velocidex Velociraptor has an authorization bypass vulnerability Moderate
CVE-2026-7573 was published for www.velocidex.com/golang/velociraptor (Go) May 6, 2026
ProTip! Advisories are also available from the GraphQL API