GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
308 advisories
Filter by severity
Open WebUI has Broken Access Control in Tool Valves
High
CVE-2026-34222
was published
for
open-webui
(pip)
Apr 1, 2026
Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains...
High
Unreviewed
CVE-2017-20238
was published
Apr 4, 2026
OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`
High
GHSA-v3qc-wrwx-j3pw
was published
for
openclaw
(npm)
Apr 3, 2026
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in...
High
Unreviewed
CVE-2024-40814
was published
Jul 30, 2024
The issue was addressed with improved restriction of data container access. This issue is fixed...
High
Unreviewed
CVE-2024-40783
was published
Jul 30, 2024
Parser Server's streaming file download bypasses afterFind file trigger authorization
High
CVE-2026-34784
was published
for
parse-server
(npm)
Apr 1, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
High
CVE-2026-32716
was published
for
scitokens
(pip)
Mar 31, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation
High
CVE-2026-33680
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
High
GHSA-46wh-3698-f2cx
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 29, 2026
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
High
Unreviewed
CVE-2026-4248
was published
Mar 28, 2026
An authentication issue was addressed with improved state management. This issue is fixed in iOS...
High
Unreviewed
CVE-2026-28865
was published
Mar 25, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
High
CVE-2026-33668
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
High
CVE-2026-32300
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
OpenClaw DM pairing-store identities could satisfy group allowlist authorization
High
CVE-2026-32027
was published
for
openclaw
(npm)
Mar 3, 2026
Frigte has broken access control viewer user can delete admin and other users account
High
CVE-2026-33125
was published
for
frigate
(pip)
Mar 18, 2026
Juju has unauthorized update of out-of-scope Vault secrets
High
CVE-2026-32692
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
High
GHSA-r7vr-gr74-94p8
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger agent pipeline
High
CVE-2026-28448
was published
for
openclaw
(npm)
Feb 17, 2026
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
High
CVE-2026-3009
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 5, 2026
OpenClaw Slack: dmPolicy=open allowed any DM sender to run privileged slash commands
High
CVE-2026-28392
was published
for
openclaw
(npm)
Feb 18, 2026
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to...
High
Unreviewed
CVE-2026-0017
was published
Mar 2, 2026
Vaultwarden's Collection Management Operations Allowed Without `manage` Verification for Manager Role
High
CVE-2026-27803
was published
for
vaultwarden
(Rust)
Mar 4, 2026
INSATutorat has an authorization bypass vulnerability in its /api/admin/* endpoints
High
GHSA-xfx2-prg5-jq3g
was published
for
github.com/romitou/insatutorat
(Go)
Mar 1, 2026
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is...
High
Unreviewed
CVE-2025-4521
was published
Feb 19, 2026
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over...
High
Unreviewed
CVE-2026-20960
was published
Jan 17, 2026
ProTip!
Advisories are also available from the
GraphQL API