GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
29,081 advisories
Filter by severity
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local...
Critical
Unreviewed
CVE-2026-32746
was published
Mar 13, 2026
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to...
Critical
Unreviewed
CVE-2026-3891
was published
Mar 13, 2026
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and...
Critical
Unreviewed
CVE-2026-25823
was published
Mar 13, 2026
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and...
Critical
Unreviewed
CVE-2026-25818
was published
Mar 13, 2026
wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions()...
Critical
Unreviewed
CVE-2026-22193
was published
Mar 13, 2026
OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes
Critical
GHSA-rqpp-rjj8-7wv8
was published
for
openclaw
(npm)
Mar 13, 2026
Apollo Federation vulnerable to prototype pollution via incomplete key sanitization
Critical
CVE-2026-32621
was published
for
@apollo/federation-internals
(npm)
Mar 13, 2026
Centrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URL
Critical
CVE-2026-32301
was published
for
github.com/centrifugal/centrifugo/v6
(Go)
Mar 13, 2026
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
Critical
CVE-2026-32306
was published
for
oneuptime
(npm)
Mar 13, 2026
Locutus vulnerable to RCE via unsanitized input in create_function()
Critical
CVE-2026-32304
was published
for
locutus
(npm)
Mar 13, 2026
SM9 Infinity-Point Ciphertext Forgery Vulnerability
Critical
CVE-2026-32614
was published
for
github.com/emmansun/gmsm
(Go)
Mar 13, 2026
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
Critical
GHSA-4jpw-hj22-2xmc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes
Critical
GHSA-xw77-45gv-p728
was published
for
openclaw
(npm)
Mar 13, 2026
Dagu: Path Traversal via `dagRunId` in Inline DAG Execution
Critical
CVE-2026-31886
was published
for
github.com/dagu-org/dagu
(Go)
Mar 13, 2026
SandboxJS affected by a Sandbox Escape
Critical
CVE-2026-26954
was published
for
@nyariv/sandboxjs
(npm)
Mar 13, 2026
The Honeywell IQ4x building management controller, exposes its full web-based HMI without...
Critical
Unreviewed
CVE-2026-3611
was published
Mar 12, 2026
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform...
Critical
Unreviewed
CVE-2025-70245
was published
Mar 12, 2026
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2026-26793
was published
Mar 12, 2026
TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
Critical
CVE-2026-28792
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+,...
Critical
Unreviewed
CVE-2026-28252
was published
Mar 12, 2026
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2026-26791
was published
Mar 12, 2026
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities...
Critical
Unreviewed
CVE-2026-26792
was published
Mar 12, 2026
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2026-26795
was published
Mar 12, 2026
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres...
Critical
Unreviewed
CVE-2026-21708
was published
Mar 12, 2026
Parse Server: Account takeover via operator injection in authentication data identifier
Critical
CVE-2026-32248
was published
for
parse-server
(npm)
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API