GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
87 advisories
Filter by severity
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Critical
CVE-2026-55518
was published
for
avo
(RubyGems)
Jun 17, 2026
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
Critical
CVE-2026-47407
was published
for
praisonai-platform
(pip)
May 29, 2026
free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptions
Critical
CVE-2026-44330
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
Critical
CVE-2026-43999
was published
for
vm2
(npm)
May 7, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
Critical
CVE-2026-41050
was published
for
github.com/rancher/fleet
(Go)
May 7, 2026
Axonflow fixed bugs by implementing multi-tenant isolation and access-control hardening
Critical
GHSA-9h64-2846-7x7f
was published
for
github.com/getaxonflow/axonflow
(Go)
May 6, 2026
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
Critical
CVE-2026-43948
was published
for
wger
(pip)
May 6, 2026
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
Critical
CVE-2026-44221
was published
for
com.arcadedb:arcadedb-server
(Maven)
May 5, 2026
S3-Proxy has Security Issues in its Resource Path Matching Implementation
Critical
CVE-2026-42882
was published
for
github.com/oxyno-zeta/s3-proxy
(Go)
May 5, 2026
Codechecker has an authentication bypass for certain API calls
Critical
CVE-2026-25660
was published
for
codechecker
(pip)
May 5, 2026
Pelican Web UI Affected by a Privilege Escalation Attack
Critical
CVE-2026-42571
was published
for
github.com/pelicanplatform/pelican
(Go)
May 4, 2026
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
Critical
CVE-2026-41248
was published
for
@clerk/astro
(npm)
Apr 16, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token
Critical
CVE-2026-6290
was published
for
www.velocidex.com/golang/velociraptor
(Go)
Apr 15, 2026
changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering
Critical
CVE-2026-35490
was published
for
changedetection.io
(pip)
Apr 6, 2026
OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation
Critical
CVE-2026-41329
was published
for
openclaw
(npm)
Apr 2, 2026
PraisonAI Has Authentication Bypass via OAuthManager.validate_token()
Critical
CVE-2026-34953
was published
for
praisonai
(pip)
Apr 1, 2026
OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation
Critical
CVE-2026-33579
was published
for
openclaw
(npm)
Mar 31, 2026
parse-server has cloud function validator bypass via prototype chain traversal
Critical
CVE-2026-34532
was published
for
parse-server
(npm)
Mar 31, 2026
Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
Critical
GHSA-hh43-q692-2xmq
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity
Critical
GHSA-rwwx-25m7-ww73
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
Critical
GHSA-fqw4-mph7-2vr8
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
Critical
CVE-2026-35663
was published
for
openclaw
(npm)
Mar 27, 2026
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
Critical
CVE-2026-32767
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter
Critical
CVE-2026-30965
was published
for
parse-server
(npm)
Mar 11, 2026
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Critical
CVE-2022-31247
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API