GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
171 advisories
Filter by severity
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
High
CVE-2026-47412
was published
for
praisonai-platform
(pip)
Jun 1, 2026
praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
High
CVE-2026-47409
was published
for
praisonai-platform
(pip)
May 29, 2026
@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies
High
GHSA-4xrh-5m3m-328w
was published
for
@hulumi/policies
(npm)
May 21, 2026
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
High
CVE-2026-46617
was published
for
github.com/fission/fission
(Go)
May 21, 2026
phpMyFAQ: IDOR Account Takeover
High
CVE-2026-35671
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 20, 2026
Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration
High
CVE-2026-45716
was published
for
@budibase/worker
(npm)
May 18, 2026
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
High
CVE-2026-45675
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
High
CVE-2026-45395
was published
for
open-webui
(npm)
May 14, 2026
wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
High
CVE-2026-43978
was published
for
wger
(pip)
May 14, 2026
Low-privileged Grav API users can create super-admin accounts via blueprint-upload
High
CVE-2026-42844
was published
for
getgrav/grav
(Composer)
May 6, 2026
Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
High
CVE-2026-42609
was published
for
getgrav/grav
(Composer)
May 5, 2026
Duplicate Advisory: OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send
High
GHSA-394x-274p-mqc6
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Neko has a Self-service Privilege Escalation for Authenticated Users
High
CVE-2026-39386
was published
for
github.com/m1k1o/neko/server
(Go)
Apr 21, 2026
Weblate: Privilege escalation in the user API endpoint
High
CVE-2026-34393
was published
for
weblate
(pip)
Apr 16, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
High
CVE-2026-38529
was published
for
krayin/laravel-crm
(Composer)
Apr 14, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting
High
CVE-2026-35595
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
High
CVE-2026-35607
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send
High
CVE-2026-41359
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing
High
CVE-2026-41386
was published
for
openclaw
(npm)
Apr 3, 2026
File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution
High
CVE-2026-34528
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 31, 2026
OpenClaw: Gateway operator.write Can Reach Admin-Class Channel Allowlist Persistence via chat.send
High
CVE-2026-35621
was published
for
openclaw
(npm)
Mar 30, 2026
Ella Core has Privilege Escalation via Database Restore by NetworkManager role
High
CVE-2026-33906
was published
for
github.com/ellanetworks/core
(Go)
Mar 26, 2026
Signify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
High
CVE-2025-70887
was published
for
signify
(pip)
Mar 25, 2026
pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration
High
CVE-2026-33509
was published
for
pyload-ng
(pip)
Mar 20, 2026
OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval
High
GHSA-63f5-hhc7-cx6p
was published
for
openclaw
(npm)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API