GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
OpenClaw: Bonjour/DNS-SD TXT metadata steers CLI routing after failed service resolution
Moderate
GHSA-rvqr-hrcc-j9vv
was published
for
openclaw
(npm)
Mar 26, 2026
An error in the SignServer container startup logic was found in Keyfactor SignServer versions...
Moderate
Unreviewed
CVE-2025-26787
was published
Dec 22, 2025
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution...
High
Unreviewed
CVE-2025-49090
was published
Oct 2, 2025
Duplicate Advisory: Unauthenticated Nonce Increment in snow
Low
GHSA-97f8-h76h-f297
was published
for
snow
(Rust)
Jul 28, 2025
•
withdrawn
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue...
Moderate
Unreviewed
CVE-2025-54566
was published
Jul 25, 2025
An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7,...
Moderate
Unreviewed
CVE-2024-8754
was published
Sep 12, 2024
External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000...
Moderate
Unreviewed
CVE-2024-22387
was published
Jul 11, 2024
On Unix platforms, the Go runtime does not behave differently when a binary is run with the...
High
Unreviewed
CVE-2023-29403
was published
Jun 8, 2023
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection'...
Critical
Unreviewed
CVE-2023-0575
was published
Feb 9, 2023
A logic issue was addressed with improved state management. This issue is fixed in iOS 16....
Moderate
Unreviewed
CVE-2022-32859
was published
Nov 2, 2022
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to...
High
Unreviewed
CVE-2018-15382
was published
May 13, 2022
In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the...
Moderate
Unreviewed
CVE-2022-22154
was published
Jan 20, 2022
Bypassing Sanitization using DOM clobbering in html-janitor
Moderate
CVE-2017-0928
was published
for
html-janitor
(npm)
Jul 24, 2018
ProTip!
Advisories are also available from the
GraphQL API