GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
212 advisories
Filter by severity
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
High
CVE-2026-45301
was published
for
open-webui
(pip)
May 14, 2026
wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
High
CVE-2026-43977
was published
for
wger
(pip)
May 14, 2026
FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-46441
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
High
CVE-2026-42863
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-42862
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-42861
was published
for
flowise
(npm)
May 14, 2026
Open WebUI's responses passthrough endpoint lacks access control authorization
High
CVE-2026-44556
was published
for
open-webui
(pip)
May 8, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
High
CVE-2026-42222
was published
for
github.com/0xJacky/nginx-ui
(Go)
May 6, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
High
CVE-2025-67796
was published
for
rdiffweb
(pip)
May 4, 2026
OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens
High
CVE-2026-44118
was published
for
openclaw
(npm)
May 4, 2026
Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
High
CVE-2026-42205
was published
for
avo
(RubyGems)
Apr 24, 2026
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
High
CVE-2026-41900
was published
for
openlearnx
(npm)
Apr 23, 2026
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
High
CVE-2026-33318
was published
for
@actual-app/sync-server
(npm)
Apr 23, 2026
@nocobase/plugin-collection-sql: SQL Validation Bypass Through Missing `checkSQL` Call
High
CVE-2026-41641
was published
for
@nocobase/plugin-collection-sql
(npm)
Apr 22, 2026
OpenRemote has Improper Access Control via updateUserRealmRoles function
High
CVE-2026-41166
was published
for
io.openremote:openremote-manager
(Maven)
Apr 22, 2026
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
High
CVE-2026-22754
was published
for
org.springframework.security:spring-security-config
(Maven)
Apr 22, 2026
Neko has a Self-service Privilege Escalation for Authenticated Users
High
CVE-2026-39386
was published
for
github.com/m1k1o/neko/server
(Go)
Apr 21, 2026
OpenClaude: Sandbox Bypass via Early-Exit Logic Flaw Allows Path Traversal
High
CVE-2026-35570
was published
for
@gitlawb/openclaude
(npm)
Apr 21, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens
High
CVE-2026-33031
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Apr 21, 2026
Dapr: Service Invocation path traversal ACL bypass
High
CVE-2026-41491
was published
for
github.com/dapr/dapr
(Go)
Apr 17, 2026
OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0
High
GHSA-525j-hqq2-66r4
was published
for
openclaw
(npm)
Apr 17, 2026
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
High
CVE-2026-41277
was published
for
flowise
(npm)
Apr 17, 2026
Paperclip: codex_local inherited ChatGPT/OpenAI-connected Gmail and was able to send real email
High
GHSA-gqqj-85qm-8qhf
was published
for
paperclipai
(npm)
Apr 16, 2026
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
High
CVE-2026-41270
was published
for
flowise
(npm)
Apr 16, 2026
wger has Broken Access Control in Global Gym Configuration Update Endpoint
High
CVE-2026-40474
was published
for
wger
(pip)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API