GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
31 advisories
Filter by severity
Home Assistant MCP Server: YAML config backups written under www/ are served unauthenticated at /local/
Moderate
GHSA-g39v-cvjh-8fpf
was published
for
ha-mcp
(pip)
May 14, 2026
@axonflow/openclaw fix introduces plugin cache and credential-file permission hardening
Moderate
GHSA-cqmh-pcgr-q42f
was published
for
@axonflow/openclaw
(npm)
May 6, 2026
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
Moderate
CVE-2026-32750
was published
for
github.com/siyuan-note/siyuan
(Go)
Mar 16, 2026
TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction
Moderate
CVE-2026-29066
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
Liferay Portal Unauthenticated File Access via URL
Moderate
CVE-2025-43749
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import Functionality
Moderate
CVE-2025-66625
was published
for
Umbraco.Cms
(NuGet)
Dec 9, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
Moderate
GHSA-f5p4-p5q5-jv3h
was published
for
github.com/edgelesssys/contrast
(Go)
Oct 28, 2025
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
Moderate
CVE-2024-40767
was published
for
Nova
(pip)
Jul 24, 2024
Guava vulnerable to insecure use of temporary directory
Moderate
CVE-2023-2976
was published
for
com.google.guava:guava
(Maven)
Jun 14, 2023
TCPDF Local File Inclusion vulnerability
Moderate
CVE-2024-51058
was published
for
tecnickcom/tcpdf
(Composer)
Nov 26, 2024
Vert.x-Web Access Control Flaw in StaticHandler’s Hidden File Protection for Files Under Hidden Directories
Moderate
CVE-2025-11965
was published
for
io.vertx:vertx-web
(Maven)
Oct 22, 2025
copyparty: Sharing a single file does not fully restrict access to other files in source folder
Moderate
CVE-2025-58753
was published
for
copyparty
(pip)
Sep 9, 2025
Liferay Portal's unauthenticated users can access loaded files via URL before submitting the object entry
Moderate
CVE-2025-43758
was published
for
com.liferay:com.liferay.frontend.js.web
(Maven)
Aug 22, 2025
Markdownify MCP Server allows attackers to read arbitrary files
Moderate
CVE-2025-5273
was published
for
mcp-markdownify-server
(npm)
May 29, 2025
Jenkins NUnit Plugin vulnerable to Protection Mechanism Failure
Moderate
CVE-2022-43414
was published
for
org.jenkins-ci.plugins:nunit
(Maven)
Oct 19, 2022
In AshPostgres, empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.
Moderate
CVE-2024-49756
was published
for
ash_postgres
(Erlang)
Oct 23, 2024
OpenStack Swift XML external entities (XXE) Injection
Moderate
CVE-2022-47950
was published
for
swift
(pip)
Jan 18, 2023
Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability
Moderate
CVE-2024-45627
was published
for
org.apache.linkis:linkis-metadata-query-service-jdbc
(Maven)
Jan 14, 2025
wolfictl leaks GitHub tokens to remote non-GitHub git servers
Moderate
CVE-2024-35183
was published
for
github.com/wolfi-dev/wolfictl
(Go)
May 15, 2024
Scrapy allows redirect following in protocols other than HTTP
Moderate
GHSA-23j4-mw76-5v7h
was published
for
Scrapy
(pip)
May 14, 2024
Drupal core access bypass vulnerability
Moderate
CVE-2017-6922
was published
for
drupal/core
(Composer)
May 13, 2022
Broken access control on files
Moderate
CVE-2019-14273
was published
for
silverstripe/framework
(Composer)
Jul 15, 2020
Missing authorization in xwiki-platform
Moderate
CVE-2022-23621
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Feb 9, 2022
Keycloak has Files or Directories Accessible to External Parties
Moderate
CVE-2021-3856
was published
for
org.keycloak:keycloak-core
(Maven)
Aug 27, 2022
Podman has Files or Directories Accessible to External Parties
Moderate
CVE-2020-1726
was published
for
github.com/containers/podman
(Go)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API