GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
25,562 advisories
Filter by severity
A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An...
Critical
Unreviewed
CVE-2026-5128
was published
Mar 30, 2026
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in...
Critical
Unreviewed
CVE-2026-5121
was published
Mar 30, 2026
Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the...
Critical
Unreviewed
CVE-2026-4415
was published
Mar 30, 2026
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5...
Critical
Unreviewed
CVE-2026-4176
was published
Mar 29, 2026
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf...
Critical
Unreviewed
CVE-2026-32915
was published
Mar 29, 2026
OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate...
Critical
Unreviewed
CVE-2026-32922
was published
Mar 29, 2026
OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals...
Critical
Unreviewed
CVE-2026-32978
was published
Mar 29, 2026
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing...
Critical
Unreviewed
CVE-2026-32987
was published
Mar 29, 2026
GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe...
Critical
Unreviewed
CVE-2026-4851
was published
Mar 29, 2026
HTTP::Session versions through 0.53 for Perl defaults to using insecurely generated session ids.
...
Critical
Unreviewed
CVE-2026-3256
was published
Mar 28, 2026
Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security...
Critical
Unreviewed
CVE-2025-15604
was published
Mar 28, 2026
JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability...
Critical
Unreviewed
CVE-2017-20227
was published
Mar 28, 2026
MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows...
Critical
Unreviewed
CVE-2017-20229
was published
Mar 28, 2026
Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers...
Critical
Unreviewed
CVE-2018-25223
was published
Mar 28, 2026
Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute...
Critical
Unreviewed
CVE-2018-25220
was published
Mar 28, 2026
EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows...
Critical
Unreviewed
CVE-2018-25221
was published
Mar 28, 2026
JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows...
Critical
Unreviewed
CVE-2016-20049
was published
Mar 28, 2026
TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers...
Critical
Unreviewed
CVE-2017-20225
was published
Mar 28, 2026
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the...
Critical
Unreviewed
CVE-2026-30530
was published
Mar 27, 2026
The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability...
Critical
Unreviewed
CVE-2026-30302
was published
Mar 27, 2026
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the...
Critical
Unreviewed
CVE-2026-30533
was published
Mar 27, 2026
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the...
Critical
Unreviewed
CVE-2026-30532
was published
Mar 27, 2026
In its design for automatic terminal command execution, AI Code offers two options: Execute safe...
Critical
Unreviewed
CVE-2026-30304
was published
Mar 27, 2026
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for...
Critical
Unreviewed
CVE-2026-1496
was published
Mar 27, 2026
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote...
Critical
Unreviewed
CVE-2026-27876
was published
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API