GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,479
Maven
5,000+
npm
5,000+
NuGet
886
pip
4,740
Pub
13
RubyGems
1,031
Rust
1,225
Swift
53
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to...
High
Unreviewed
CVE-2018-15382
was published
May 13, 2022
In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the...
Moderate
Unreviewed
CVE-2022-22154
was published
Jan 20, 2022
Bypassing Sanitization using DOM clobbering in html-janitor
Moderate
CVE-2017-0928
was published
for
html-janitor
(npm)
Jul 24, 2018
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection'...
Critical
Unreviewed
CVE-2023-0575
was published
Feb 9, 2023
External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000...
Moderate
Unreviewed
CVE-2024-22387
was published
Jul 11, 2024
An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7,...
Moderate
Unreviewed
CVE-2024-8754
was published
Sep 12, 2024
On Unix platforms, the Go runtime does not behave differently when a binary is run with the...
High
Unreviewed
CVE-2023-29403
was published
Jun 8, 2023
A logic issue was addressed with improved state management. This issue is fixed in iOS 16....
Moderate
Unreviewed
CVE-2022-32859
was published
Nov 2, 2022
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue...
Moderate
Unreviewed
CVE-2025-54566
was published
Jul 25, 2025
Duplicate Advisory: Unauthenticated Nonce Increment in snow
Low
GHSA-97f8-h76h-f297
was published
for
snow
(Rust)
Jul 28, 2025
•
withdrawn
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution...
High
Unreviewed
CVE-2025-49090
was published
Oct 2, 2025
An error in the SignServer container startup logic was found in Keyfactor SignServer versions...
Moderate
Unreviewed
CVE-2025-26787
was published
Dec 22, 2025
OpenClaw: Bonjour/DNS-SD TXT metadata steers CLI routing after failed service resolution
Moderate
CVE-2026-35659
was published
for
openclaw
(npm)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API