GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
9,551 advisories
Filter by severity
Apache Superset OS Command Injection
High
CVE-2020-13948
was published
for
apache-superset
(pip)
May 24, 2022
pgproto3 SQL Injection via Protocol Message Size Overflow
High
GHSA-7jwh-3vrq-q3m8
was published
for
github.com/jackc/pgproto3
(Go)
Mar 4, 2024
Apache Libcloud does not verify SSL certificates for HTTPS connections
High
CVE-2010-4340
was published
for
apache-libcloud
(pip)
May 17, 2022
Angular vulnerable to XSS in i18n attribute bindings
High
CVE-2026-32635
was published
for
@angular/compiler
(npm)
Mar 13, 2026
simplesamlphp/xml-security: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
High
CVE-2026-32600
was published
for
simplesamlphp/xml-security
(Composer)
Mar 13, 2026
Yamux vulnerable to remote Panic via malformed Data frame with SYN set and len = 262145
High
CVE-2026-32314
was published
for
yamux
(Rust)
Mar 13, 2026
xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
High
CVE-2026-32313
was published
for
robrichards/xmlseclibs
(Composer)
Mar 13, 2026
github.com/ctfer-io/monitoring Vulnerable to Improper Access Control
High
CVE-2026-32720
was published
for
github.com/ctfer-io/monitoring
(Go)
Mar 13, 2026
SimpleEval: Objects (including modules) can leak dangerous modules through to direct access inside the sandbox
High
CVE-2026-32640
was published
for
simpleeval
(pip)
Mar 13, 2026
Admidio has a Second-Order SQL Injection via List Configuration (lsc_special_field, lsc_sort, lsc_filter)
High
CVE-2026-32813
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
High
CVE-2026-32264
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
High
CVE-2026-32263
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin
High
CVE-2026-32261
was published
for
craftcms/webhooks
(Composer)
Mar 16, 2026
Romeo is vulnerable to Archive Slip due to missing checks in sanitization
High
CVE-2026-32805
was published
for
github.com/ctfer-io/romeo/webserver
(Go)
Mar 16, 2026
Monitoring is vulnerable to Archive Slip due to missing checks in sanitization
High
CVE-2026-32771
was published
for
github.com/ctfer-io/monitoring
(Go)
Mar 16, 2026
Fullchain's Invalid NetworkPolicy enables a malicious actor to pivot into another namespace
High
CVE-2026-32769
was published
for
github.com/ctfer-io/fullchain
(Go)
Mar 16, 2026
Chall-Manager's invalid NetworkPolicy enables a malicious actor to pivot into another namespace
High
CVE-2026-32768
was published
for
github.com/ctfer-io/chall-manager/deploy
(Go)
Mar 16, 2026
FastMCP OAuth Proxy token reuse across MCP servers
High
CVE-2025-69196
was published
for
fastmcp
(pip)
Mar 16, 2026
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
High
CVE-2026-28498
was published
for
authlib
(pip)
Mar 16, 2026
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
High
CVE-2026-28490
was published
for
authlib
(pip)
Mar 16, 2026
OpenClaw Improperly Neutralizes Line Breaks in systemd Unit Generation Enables Local Command Execution (Linux)
High
CVE-2026-32063
was published
for
openclaw
(npm)
Mar 3, 2026
File Upload(RCE) Vulnerability in admidio
High
CVE-2026-32756
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Loop with Unreachable Exit Condition ('Infinite Loop') in ewe
High
GHSA-4w98-xf39-23gp
was published
for
ewe
(Erlang)
Mar 16, 2026
lz4_flex's decompression can leak information from uninitialized memory or reused output buffer
High
GHSA-vvp9-7p8x-rfvv
was published
for
lz4_flex
(Rust)
Mar 16, 2026
Romeo's invalid NetworkPolicy enables a malicious actor to pivot into another namespace
High
CVE-2026-32737
was published
for
github.com/ctfer-io/romeo/environment/deploy
(Go)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API