GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,557 advisories
Filter by severity
File Browser Signup Grants Admin When Default Permissions Include Admin
Critical
CVE-2026-32760
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 16, 2026
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
Moderate
GHSA-v3mg-9v85-fcm7
was published
for
siyuan
(Go)
Mar 16, 2026
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely
Moderate
CVE-2026-32759
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 16, 2026
OpenClaw session transcript files were created without forced user-only permissions
Moderate
GHSA-vr7j-g7jv-h5mp
was published
for
openclaw
(npm)
Mar 16, 2026
OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection
High
GHSA-g2f6-pwvx-r275
was published
for
openclaw
(npm)
Mar 16, 2026
OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion
High
GHSA-jq3f-vjww-8rq7
was published
for
openclaw
(npm)
Mar 16, 2026
OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval
High
GHSA-63f5-hhc7-cx6p
was published
for
openclaw
(npm)
Mar 16, 2026
OpenClaw Telegram media fetch errors exposed bot tokens in logged file URLs
Moderate
GHSA-xwcj-hwhf-h378
was published
for
openclaw
(npm)
Mar 16, 2026
SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface
Moderate
CVE-2026-32751
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
Moderate
CVE-2026-32750
was published
for
github.com/siyuan-note/siyuan
(Go)
Mar 16, 2026
SiYuan importSY/importZipMd: path traversal via multipart filename enables arbitrary file write
High
CVE-2026-32749
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
SiYuan Vulnerable to Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure
Moderate
CVE-2026-32815
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
SiYuan globalCopyFiles: incomplete sensitive path blocklist allows reading /proc and Docker secrets
Moderate
CVE-2026-32747
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
High
CVE-2026-32728
was published
for
parse-server
(npm)
Mar 16, 2026
Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability
High
CVE-2026-32268
was published
for
craftcms/azure-blob
(Composer)
Mar 16, 2026
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
High
CVE-2026-32267
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
High
CVE-2026-30405
was published
for
github.com/osrg/gobgp/v4
(Go)
Mar 16, 2026
Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability
Low
CVE-2026-32266
was published
for
craftcms/google-cloud
(Composer)
Mar 16, 2026
Amazon S3 for Craft CMS has an Information Disclosure vulnerability
Moderate
CVE-2026-32265
was published
for
craftcms/aws-s3
(Composer)
Mar 16, 2026
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
High
CVE-2026-32264
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
High
CVE-2026-32263
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Craft CMS has a Path Traversal Vulnerability in AssetsController
Moderate
CVE-2026-32262
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin
High
CVE-2026-32261
was published
for
craftcms/webhooks
(Composer)
Mar 16, 2026
SandboxJS has an execution-quota bypass (cross-sandbox currentTicks race) in SandboxJS timers
Moderate
CVE-2026-32723
was published
for
@nyariv/sandboxjs
(npm)
Mar 16, 2026
Stored XSS in Memray-generated HTML reports via unescaped command-line metadata
Low
CVE-2026-32722
was published
for
memray
(pip)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API