Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

52 advisories

Loading
wlc may disclose API tokens to project-configured URLs Low
CVE-2026-62364 was published for wlc (pip) Sep 22, 2026
nijel Credited to nijel, type5afe, and visionxstack type5afe type5afe
visionxstack visionxstack
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) Moderate
CVE-2026-54625 was published for django-cms (pip) Aug 24, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, and mauriceng98 7thParkk 7thParkk
mauriceng98 mauriceng98
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning Low
CVE-2026-46342 was published for @nuxt/nitro-server (npm) May 19, 2026
fancymalware Credited to fancymalware
Next.js's Middleware / Proxy redirects can be cache-poisoned Low
CVE-2026-44572 was published for next (npm) May 11, 2026
OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders Moderate
CVE-2026-41354 was published for openclaw (npm) Apr 7, 2026
D0ub1e-D Credited to D0ub1e-D
OpenClaw has an Arbitrary Malicious Code Execution Vulnerability High
CVE-2026-35641 was published for openclaw (npm) Mar 30, 2026
ChangeYourWay Credited to ChangeYourWay
ProTip! Advisories are also available from the GraphQL API