GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,288 advisories
Filter by severity
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible...
High
Unreviewed
CVE-2026-4896
was published
Apr 4, 2026
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the...
Critical
Unreviewed
CVE-2026-25197
was published
Apr 3, 2026
** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when...
Moderate
Unreviewed
CVE-2026-28736
was published
Apr 3, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster
Low
CVE-2026-5199
was published
for
go.temporal.io/server
(Go)
Apr 1, 2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor...
Moderate
Unreviewed
CVE-2026-3139
was published
Mar 31, 2026
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel...
High
Unreviewed
CVE-2026-32976
was published
Mar 31, 2026
Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows...
High
Unreviewed
CVE-2026-4400
was published
Mar 31, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys
High
CVE-2026-33030
was published
for
github.com/0xJacky/nginx-ui
(Go)
Mar 30, 2026
A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1...
High
Unreviewed
CVE-2026-3321
was published
Mar 30, 2026
The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
High
Unreviewed
CVE-2026-3124
was published
Mar 30, 2026
OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName
Moderate
GHSA-52q4-3xjc-6778
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility
High
GHSA-q2qc-744p-66r2
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: Gateway HTTP Session History Route Bypasses Operator Read Scope
Moderate
GHSA-5jvj-hxmh-6h6j
was published
for
openclaw
(npm)
Mar 29, 2026
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
High
CVE-2026-34046
was published
for
langflow
(pip)
Mar 27, 2026
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
High
CVE-2026-33946
was published
for
mcp
(RubyGems)
Mar 27, 2026
Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
Low
CVE-2026-29071
was published
for
open-webui
(pip)
Mar 27, 2026
Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
High
CVE-2026-28788
was published
for
open-webui
(pip)
Mar 27, 2026
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for...
Critical
Unreviewed
CVE-2026-1496
was published
Mar 27, 2026
OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens
Moderate
GHSA-xhq5-45pm-2gjr
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Synology Chat reply delivery could be rebound through username-based user resolution.
High
GHSA-wv46-v6xc-2qhf
was published
for
openclaw
(npm)
Mar 26, 2026
AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcriptions
Moderate
CVE-2026-33764
was published
for
wwbn/avideo
(Composer)
Mar 26, 2026
AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents
Moderate
CVE-2026-33759
was published
for
wwbn/avideo
(Composer)
Mar 26, 2026
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Low
GHSA-44px-qjjc-xrhq
was published
for
craftcms/cms
(Composer)
Mar 26, 2026
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
Critical
GHSA-2pv8-4c52-mf8j
was published
for
code.vikunja.io/api
(Go)
Mar 26, 2026
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to...
Moderate
Unreviewed
CVE-2026-1206
was published
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API