GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
44 advisories
Filter by severity
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper...
Moderate
Unreviewed
CVE-2024-23565
was published
Jul 17, 2026
Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library...
High
Unreviewed
CVE-2026-5233
was published
Jun 15, 2026
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS...
High
Unreviewed
CVE-2026-7402
was published
Apr 30, 2026
Duplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting
Moderate
GHSA-w9f5-8q83-qwpx
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification
Moderate
GHSA-2hv5-4h3g-4hjv
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Pairing pending-request caps were enforced per channel instead of per account
Moderate
GHSA-mf69-r24q-ghhr
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
OpenClaw: Pairing pending-request caps were enforced per channel instead of per account
Moderate
CVE-2026-41346
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting
Moderate
CVE-2026-41333
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification
Moderate
CVE-2026-41343
was published
for
openclaw
(npm)
Apr 2, 2026
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive...
Moderate
Unreviewed
CVE-2025-55268
was published
Mar 26, 2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of...
Moderate
Unreviewed
CVE-2025-13212
was published
Mar 16, 2026
wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated...
Moderate
Unreviewed
CVE-2026-22216
was published
Mar 13, 2026
Parse Server has a rate limit bypass via batch request endpoint
Moderate
CVE-2026-30972
was published
for
parse-server
(npm)
Mar 11, 2026
An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet...
High
Unreviewed
CVE-2026-24017
was published
Mar 10, 2026
OpenClaw's hooks count non-POST requests toward auth lockout
Moderate
GHSA-6rmx-gvvg-vh6j
was published
for
openclaw
(npm)
Mar 9, 2026
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial...
Moderate
Unreviewed
CVE-2025-13211
was published
Dec 11, 2025
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password...
Critical
Unreviewed
CVE-2025-54321
was published
Nov 18, 2025
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Moderate
CVE-2025-57816
was published
for
ethyca-fides
(pip)
Sep 8, 2025
OpenFlow discovery protocol can exhaust resources because it is not rate limited
Moderate
Unreviewed
CVE-2025-48016
was published
May 20, 2025
Shopware default newsletter opt-in settings allow for mass sign-up abuse
Low
CVE-2025-32378
was published
for
shopware/core
(Composer)
Apr 9, 2025
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP...
High
Unreviewed
CVE-2025-29998
was published
Mar 13, 2025
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP...
Moderate
Unreviewed
CVE-2025-26524
was published
Feb 14, 2025
Missing rate limit in MaysWind ezBookkeeping
Moderate
CVE-2024-57603
was published
for
github.com/mayswind/ezbookkeeping
(Go)
Feb 13, 2025
Drupal Open Social allows Functionality Misuse
Moderate
CVE-2024-13274
was published
for
goalgorilla/open_social
(Composer)
Jan 9, 2025
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API...
High
Unreviewed
CVE-2024-51557
was published
Nov 4, 2024
ProTip!
Advisories are also available from the
GraphQL API