GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,429
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,680
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,575 advisories
Filter by severity
OpenClaw: Discord voice transcript owner-flag omission could expose owner-only tools in mixed-trust channels
Moderate
CVE-2026-32035
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Sandboxed sessions_spawn(runtime="acp") bypassed sandbox inheritance and allowed host ACP initialization
High
GHSA-474h-prjg-mmw3
was published
for
openclaw
(npm)
Mar 3, 2026
MCP NMAP Server has an Injection vulnerability
Moderate
CVE-2026-3484
was published
for
mcp-nmap-server
(npm)
Mar 3, 2026
OpenClaw has encoded-path auth bypass in plugin `/api/channels` route classification
High
CVE-2026-32004
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups
Moderate
CVE-2026-32028
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: ZIP extraction race could write outside destination via parent symlink rebind
High
CVE-2026-28483
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows
Moderate
CVE-2026-22180
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's web tools strict URL guard could lose DNS pinning when env proxy is configured
Moderate
CVE-2026-22181
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts
Moderate
CVE-2026-29608
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots
Moderate
GHSA-2858-xg23-26fp
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has pre-auth webhook body parsing that can enable unauthenticated slow-request DoS
Moderate
CVE-2026-32011
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace
High
CVE-2026-31990
was published
for
openclaw
(npm)
Mar 3, 2026
SiYuan's direct SQL Query API accessible to Reader-level users enables unauthorized database access
Moderate
CVE-2026-29073
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 3, 2026
Craft CMS has potential authenticated Remote Code Execution via Twig SSTI
Moderate
CVE-2026-28784
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has Permission Bypass and IDOR in Duplicate Entry Action
Moderate
CVE-2026-28782
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has Twig Function Blocklist Bypass
Moderate
CVE-2026-28783
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS: Entries Authorship Spoofing via Mass Assignment
Moderate
CVE-2026-28781
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates
Critical
CVE-2026-28697
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells
Moderate
CVE-2026-28401
was published
for
nocodb
(npm)
Mar 3, 2026
NocoDB Vulnerable to Stored Cross-site Scripting via Comments
Moderate
CVE-2026-28397
was published
for
nocodb
(npm)
Mar 3, 2026
NocoDB Vulnerable to SQL Injection via DATEADD Formula
Moderate
CVE-2026-28399
was published
for
nocodb
(npm)
Mar 3, 2026
NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells
Moderate
CVE-2026-28398
was published
for
nocodb
(npm)
Mar 3, 2026
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
Low
GHSA-4mgv-366x-qxvx
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has IDOR via GraphQL @parseRefs
High
CVE-2026-28696
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Moderate
CVE-2026-28695
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API