GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
35,755 advisories
Filter by severity
RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
High
CVE-2026-21862
was published
for
rustfs
(Rust)
Feb 3, 2026
Decidim's private data exports can lead to data leaks
High
CVE-2025-65017
was published
for
decidim
(RubyGems)
Feb 3, 2026
Django has Observable Timing Discrepancy
Low
CVE-2025-13473
was published
for
Django
(pip)
Feb 3, 2026
Django has Inefficient Algorithmic Complexity
Low
CVE-2026-1285
was published
for
Django
(pip)
Feb 3, 2026
Django has Inefficient Algorithmic Complexity
Low
CVE-2025-14550
was published
for
Django
(pip)
Feb 3, 2026
Moodle Open Redirect vulnerability
Low
CVE-2025-67852
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle Affected by Improper Restriction of Excessive Authentication Attempts
High
CVE-2025-67853
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle vulnerable to Cross-site Scripting
Moderate
CVE-2025-67855
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle Inserts Sensitive Information Into Sent Data
Moderate
CVE-2025-67857
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle has an authorization logic flaw
Moderate
CVE-2025-67856
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle authentication bypass vulnerability
High
CVE-2025-67848
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle formula injection vulnerability
Moderate
CVE-2025-67851
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle vulnerable to Cross-site Scripting
High
CVE-2025-67850
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Moodle Cross-site Scripting (XSS) vulnerability
High
CVE-2025-67849
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Tendenci CMS Contains a Cross-site Scripting Vulnerability in its Jobs Module
Moderate
CVE-2025-70959
was published
for
tendenci
(pip)
Feb 3, 2026
Tendenci CMS contains a stored Cross-site Scripting (XSS) vulnerability in the Forums module
Moderate
CVE-2025-70960
was published
for
tendenci
(pip)
Feb 3, 2026
Subrion CMS vulnerable to cross-site scripting
Moderate
CVE-2025-70958
was published
for
intelliants/subrion
(Composer)
Feb 3, 2026
OpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommand
High
CVE-2026-25157
was published
for
clawdbot
(npm)
Feb 2, 2026
OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl
High
CVE-2026-25253
was published
for
clawdbot
(npm)
Feb 2, 2026
OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable
High
CVE-2026-24763
was published
for
clawdbot
(npm)
Feb 2, 2026
SageMaker Python SDK has Exposed HMAC
High
CVE-2026-1777
was published
for
sagemaker
(pip)
Feb 2, 2026
SageMaker Python SDK has Insecure TLS Configuration
High
CVE-2026-1778
was published
for
sagemaker
(pip)
Feb 2, 2026
ProTip!
Advisories are also available from the
GraphQL API