GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
29,708 advisories
Filter by severity
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in...
Critical
Unreviewed
CVE-2026-5121
was published
Mar 30, 2026
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
Critical
GHSA-vqx2-fgx2-5wq9
was published
for
@clerk/astro
(npm)
Apr 16, 2026
A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability...
Critical
Unreviewed
CVE-2026-6644
was published
Apr 20, 2026
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated...
Critical
Unreviewed
CVE-2026-5964
was published
Apr 20, 2026
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated...
Critical
Unreviewed
CVE-2026-5963
was published
Apr 20, 2026
SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow...
Critical
Unreviewed
CVE-2026-32956
was published
Apr 20, 2026
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath...
Critical
Unreviewed
CVE-2025-49794
was published
Jun 16, 2025
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML...
Critical
Unreviewed
CVE-2025-49796
was published
Jun 16, 2025
Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI
Critical
GHSA-9qhq-v63v-fv3j
was published
for
praisonai
(pip)
Apr 17, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
Critical
GHSA-xjvp-7243-rg9h
was published
for
charm.land/wish/v2
(Go)
Apr 18, 2026
Arbitrary code execution in protobufjs
Critical
CVE-2026-41242
was published
for
protobufjs
(npm)
Apr 16, 2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the...
Critical
Unreviewed
CVE-2026-37339
was published
Apr 16, 2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the...
Critical
Unreviewed
CVE-2026-37340
was published
Apr 16, 2026
Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling
Critical
GHSA-8m29-fpq5-89jj
was published
for
zebra-script
(Rust)
Apr 18, 2026
Zebra has rk Identity Point Panic in Transaction Verification
Critical
GHSA-452v-w3gx-72wg
was published
for
zebra-chain
(Rust)
Apr 18, 2026
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
Critical
GHSA-6g38-8j4p-j3pr
was published
for
github.com/nhost/nhost
(Go)
Apr 18, 2026
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
Critical
GHSA-v38x-c887-992f
was published
for
flowise
(npm)
Apr 18, 2026
pgx contains memory-safety vulnerability
Critical
CVE-2026-33815
was published
for
github.com/jackc/pgx/v5/pgproto3
(Go)
Apr 7, 2026
OpenClaw: Feishu webhook and card-action validation now fail closed
Critical
GHSA-xh72-v6v9-mwhc
was published
for
openclaw
(npm)
Apr 17, 2026
Remote Code Execution (RCE) via String Literal Injection into math-codegen
Critical
GHSA-p6x5-p4xf-cc4r
was published
for
math-codegen
(npm)
Apr 17, 2026
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted ...
Critical
Unreviewed
CVE-2026-35546
was published
Apr 17, 2026
OpenViking prior to commit c7bb167 contains an authentication bypass vulnerability in the...
Critical
Unreviewed
CVE-2026-40525
was published
Apr 17, 2026
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this...
Critical
Unreviewed
CVE-2026-34865
was published
Apr 13, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
Critical
CVE-2026-27197
was published
for
sentry
(pip)
Apr 17, 2026
Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
Critical
CVE-2026-23500
was published
for
dolibarr/dolibarr
(Composer)
Apr 17, 2026
ProTip!
Advisories are also available from the
GraphQL API