GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
430 advisories
Filter by severity
A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the...
Moderate
Unreviewed
CVE-2026-4563
was published
Mar 23, 2026
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-2294
was published
Mar 21, 2026
A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1....
Moderate
Unreviewed
CVE-2026-4171
was published
Mar 16, 2026
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
Moderate
CVE-2026-32704
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 13, 2026
OpenClaw: Feishu reaction events could bypass group authorization and mention gating
Moderate
GHSA-m69h-jm2f-2pv8
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
GHSA-8g75-q649-6pv6
was published
for
openclaw
(npm)
Mar 12, 2026
OneUptime has WhatsApp Resend Verification Authorization Bypass
Moderate
CVE-2026-30959
was published
for
@oneuptime/common
(npm)
Mar 10, 2026
PowerSync: Some sync filters ignored on 1.20.0 using `config.edition: 3`
Moderate
CVE-2026-30870
was published
for
@powersync/service-core
(npm)
Mar 7, 2026
Kimai's API invoice endpoint missing customer-level access control (IDOR)
Moderate
CVE-2026-28685
was published
for
kimai/kimai
(Composer)
Mar 4, 2026
OpenClaw has an opt-in insecure Control UI auth over plaintext HTTP could allow privileged access
Moderate
CVE-2026-32034
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw DM pairing-store identities could satisfy group allowlist authorization
Moderate
CVE-2026-32027
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Node exec approvals could be replayed across nodes
Moderate
GHSA-6x2m-hqfw-hvpj
was published
for
openclaw
(npm)
Mar 2, 2026
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data...
Moderate
Unreviewed
CVE-2026-2694
was published
Feb 26, 2026
A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown...
Moderate
Unreviewed
CVE-2026-3185
was published
Feb 25, 2026
A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the...
Moderate
Unreviewed
CVE-2025-15582
was published
Feb 20, 2026
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area....
Moderate
Unreviewed
CVE-2025-71242
was published
Feb 19, 2026
OpenClaw's unauthenticated Nostr profile HTTP endpoints allow remote profile/config tampering
Moderate
CVE-2026-28450
was published
for
openclaw
(npm)
Feb 17, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-20666
was published
Feb 12, 2026
An authorization issue was addressed with improved state management. This issue is fixed in iOS...
Moderate
Unreviewed
CVE-2026-20661
was published
Feb 12, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43403
was published
Feb 12, 2026
Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within...
Moderate
Unreviewed
CVE-2025-30508
was published
Feb 10, 2026
The web interface offers a functionality to export the internal SQLite database. After executing...
Moderate
Unreviewed
CVE-2025-59100
was published
Jan 26, 2026
phpMyFAQ: /api/setup/backup accessible to any authenticated user (authz missing)
Moderate
CVE-2026-24421
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 23, 2026
The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and...
Moderate
Unreviewed
CVE-2025-14348
was published
Jan 20, 2026
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed...
Moderate
Unreviewed
CVE-2026-22641
was published
Jan 15, 2026
ProTip!
Advisories are also available from the
GraphQL API