GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
48
Go
3,399
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,618
Pub
13
RubyGems
1,026
Rust
1,205
Swift
52
Unreviewed advisories
All unreviewed
5,000+
13,667 advisories
Filter by severity
A vulnerability was determined in Dialogue App up to 4.3.2 on Android. The affected element is an...
Low
Unreviewed
CVE-2026-5455
was published
Apr 3, 2026
A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to 23.7.10 on...
Low
Unreviewed
CVE-2026-5457
was published
Apr 3, 2026
A vulnerability was identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android. Impacted is an...
Low
Unreviewed
CVE-2026-5462
was published
Apr 3, 2026
A weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This...
Low
Unreviewed
CVE-2026-5458
was published
Apr 3, 2026
A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The...
Low
Unreviewed
CVE-2026-5456
was published
Apr 3, 2026
A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on...
Low
Unreviewed
CVE-2026-5453
was published
Apr 3, 2026
A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown...
Low
Unreviewed
CVE-2026-5454
was published
Apr 3, 2026
A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability...
Low
Unreviewed
CVE-2026-5452
was published
Apr 3, 2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in...
Low
Unreviewed
CVE-2026-35537
was published
Apr 3, 2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH...
Low
Unreviewed
CVE-2026-35538
was published
Apr 3, 2026
Signal K Server: Arbitrary Prototype Read via `from` Field Bypass
Low
CVE-2026-35038
was published
for
signalk-server
(npm)
Apr 3, 2026
OpenClaw: Discord voice ingress authorization can be bypassed via channel, name, and stale-role validation gaps
Low
GHSA-x2m8-53h4-6hch
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config
Low
GHSA-3pm9-5j7m-59vc
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation
Low
GHSA-rfqg-qgf8-xr9x
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding
Low
GHSA-37v6-fxx8-xjmx
was published
for
openclaw
(npm)
Apr 3, 2026
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
Low
CVE-2026-34768
was published
for
electron
(npm)
Apr 3, 2026
Electron: USB device selection not validated against filtered device list
Low
CVE-2026-34766
was published
for
electron
(npm)
Apr 3, 2026
TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`
Low
GHSA-ccgf-5rwj-j3hv
was published
for
telejson
(npm)
Apr 2, 2026
A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected...
Low
Unreviewed
CVE-2026-5420
was published
Apr 2, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS...
Low
Unreviewed
CVE-2025-43236
was published
Apr 2, 2026
OpenClaw: Security Scan Failure Does Not Block Plugin Installation (Fail-Open)
Low
GHSA-cwq8-6f96-g3q4
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API
Low
GHSA-chfm-xgc4-47rj
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Matrix thread root and reply context bypass sender allowlist
Low
GHSA-rg8m-3943-vm6q
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass
Low
GHSA-hhq4-97c2-p447
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection
Low
GHSA-89r3-6x4j-v7wf
was published
for
openclaw
(npm)
Apr 2, 2026
ProTip!
Advisories are also available from the
GraphQL API