GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup
Moderate
CVE-2026-27486
was published
for
openclaw
(npm)
Feb 18, 2026
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
Critical
CVE-2026-26016
was published
for
pterodactyl/panel
(Composer)
Feb 17, 2026
A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle...
Moderate
Unreviewed
CVE-2026-0598
was published
Feb 6, 2026
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated...
Moderate
Unreviewed
CVE-2025-36091
was published
Nov 3, 2025
Mautic vulnerable to secret data extraction via elfinder
Moderate
CVE-2025-9822
was published
for
mautic/core
(Composer)
Sep 3, 2025
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A...
High
Unreviewed
CVE-2025-43882
was published
Aug 27, 2025
TYPO3 Allows Privilege Escalation to System Maintainer
High
CVE-2025-47940
was published
for
typo3/cms-core
(Composer)
May 20, 2025
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory,...
High
Unreviewed
CVE-2024-27903
was published
Jul 8, 2024
Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability...
Moderate
Unreviewed
CVE-2024-1853
was published
Mar 15, 2024
On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA,...
Low
Unreviewed
CVE-2023-6068
was published
Mar 4, 2024
kiwi TCMS has possibility for user to update email address to unverified one
Low
CVE-2023-30544
was published
for
kiwitcms
(pip)
Apr 24, 2023
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks...
High
Unreviewed
CVE-2021-24501
was published
May 24, 2022
Unverified Ownership in Kubernetes
Moderate
CVE-2020-8554
was published
for
k8s.io/kubernetes
(Go)
Feb 8, 2022
ProTip!
Advisories are also available from the
GraphQL API