GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
295 advisories
Filter by severity
Juju has unauthorized update of out-of-scope Vault secrets
High
CVE-2026-32692
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
gRPC-Go has an authorization bypass via missing leading slash in :path
Critical
CVE-2026-33186
was published
for
google.golang.org/grpc
(Go)
Mar 18, 2026
Frigte has broken access control viewer user can delete admin and other users account
High
CVE-2026-33125
was published
for
frigate
(pip)
Mar 18, 2026
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
Moderate
CVE-2026-32704
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 13, 2026
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
High
GHSA-r7vr-gr74-94p8
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Feishu reaction events could bypass group authorization and mention gating
Moderate
GHSA-m69h-jm2f-2pv8
was published
for
openclaw
(npm)
Mar 13, 2026
Centrifugo's InsecureSkipTokenSignatureVerify flag silently disables JWT verification with no warning
Low
GHSA-q926-c743-49qj
was published
for
github.com/centrifugal/centrifugo/v6
(Go)
Mar 13, 2026
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes
Critical
GHSA-xw77-45gv-p728
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
GHSA-8g75-q649-6pv6
was published
for
openclaw
(npm)
Mar 12, 2026
OneUptime has WhatsApp Resend Verification Authorization Bypass
Moderate
CVE-2026-30959
was published
for
@oneuptime/common
(npm)
Mar 10, 2026
OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data exposure and account takeover
Critical
CVE-2026-30956
was published
for
@oneuptime/common
(npm)
Mar 10, 2026
PowerSync: Some sync filters ignored on 1.20.0 using `config.edition: 3`
Moderate
CVE-2026-30870
was published
for
@powersync/service-core
(npm)
Mar 7, 2026
SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
Critical
CVE-2026-30869
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 7, 2026
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
High
CVE-2026-3009
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 5, 2026
Kimai's API invoice endpoint missing customer-level access control (IDOR)
Moderate
CVE-2026-28685
was published
for
kimai/kimai
(Composer)
Mar 4, 2026
Vaultwarden's Collection Management Operations Allowed Without `manage` Verification for Manager Role
High
CVE-2026-27803
was published
for
vaultwarden
(Rust)
Mar 4, 2026
OpenClaw has an opt-in insecure Control UI auth over plaintext HTTP could allow privileged access
Moderate
CVE-2026-32034
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw DM pairing-store identities could satisfy group allowlist authorization
Moderate
CVE-2026-32027
was published
for
openclaw
(npm)
Mar 3, 2026
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Critical
CVE-2022-31247
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
OpenClaw: Node exec approvals could be replayed across nodes
Moderate
GHSA-6x2m-hqfw-hvpj
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Low
CVE-2026-31993
was published
for
openclaw
(npm)
Mar 2, 2026
INSATutorat has an authorization bypass vulnerability in its /api/admin/* endpoints
High
GHSA-xfx2-prg5-jq3g
was published
for
github.com/romitou/insatutorat
(Go)
Mar 1, 2026
PSI Probe: Broken access control can lead to DoS
Low
CVE-2026-3269
was published
for
com.github.psi-probe:psi-probe-core
(Maven)
Feb 27, 2026
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
Low
CVE-2026-2733
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 19, 2026
OpenClaw Slack: dmPolicy=open allowed any DM sender to run privileged slash commands
High
CVE-2026-28392
was published
for
openclaw
(npm)
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API