GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,980
Maven
5,000+
npm
4,634
NuGet
788
pip
4,321
Pub
12
RubyGems
986
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
13,279 advisories
Filter by severity
OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel Descriptions
Low
CVE-2026-24764
was published
for
openclaw
(npm)
Feb 17, 2026
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated...
Low
Unreviewed
CVE-2026-23686
was published
Feb 10, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Low
Unreviewed
CVE-2026-20601
was published
Feb 12, 2026
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP),...
Low
Unreviewed
CVE-2026-24320
was published
Feb 10, 2026
An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A...
Low
Unreviewed
CVE-2026-20642
was published
Feb 12, 2026
Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team...
Low
Unreviewed
CVE-2025-14573
was published
Feb 16, 2026
A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function...
Low
Unreviewed
CVE-2026-2555
was published
Feb 16, 2026
A permissive web security configuration may allow cross-origin restrictions enforced by modern...
Low
Unreviewed
CVE-2025-9292
was published
Feb 13, 2026
Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
Low
CVE-2025-13881
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 2, 2026
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26...
Low
Unreviewed
CVE-2026-20646
was published
Feb 12, 2026
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers,...
Low
Unreviewed
CVE-2023-28322
was published
May 26, 2023
A privacy issue was addressed with improved private data redaction for log entries. This issue is...
Low
Unreviewed
CVE-2026-20681
was published
Feb 12, 2026
Mattermost doesn't properly validate channel membership at the time of data retrieval
Low
CVE-2026-20796
was published
for
github.com/mattermost/mattermost-server
(Go)
Feb 13, 2026
A logic issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and...
Low
Unreviewed
CVE-2026-20656
was published
Feb 12, 2026
Freeform Craft Plugin CP UI (builder/integrations) has Stored Cross-Site Scripting (XSS) issue
Low
CVE-2026-26188
was published
for
solspace/craft-freeform
(Composer)
Jan 22, 2026
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on...
Low
Unreviewed
CVE-2026-0872
was published
Feb 13, 2026
The issue was resolved by sanitizing logging. This issue is fixed in iOS 26.3 and iPadOS 26.3,...
Low
Unreviewed
CVE-2026-20663
was published
Feb 12, 2026
NeuVector scanner insecurely handles passwords as command arguments
Low
CVE-2025-67860
was published
for
github.com/neuvector/scanner
(Go)
Feb 12, 2026
A path traversal vulnerability has been reported to affect File Station 5. If a local attacker...
Low
Unreviewed
CVE-2025-62856
was published
Feb 11, 2026
A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker...
Low
Unreviewed
CVE-2026-22894
was published
Feb 11, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-54155
was published
Feb 11, 2026
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote...
Low
Unreviewed
CVE-2025-54163
was published
Feb 11, 2026
An improper neutralization of directives in statically saved code ('Static Code Injection')...
Low
Unreviewed
CVE-2025-57707
was published
Feb 11, 2026
A command injection vulnerability has been reported to affect Media Streaming add-on. If an...
Low
Unreviewed
CVE-2024-56808
was published
Feb 11, 2026
An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an...
Low
Unreviewed
CVE-2024-56807
was published
Feb 11, 2026
ProTip!
Advisories are also available from the
GraphQL API