GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
6,797 advisories
Filter by severity
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &...
High
Unreviewed
CVE-2026-3445
was published
Apr 4, 2026
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2026-2826
was published
Apr 4, 2026
AVideo: Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php
Low
CVE-2026-35448
was published
for
wwbn/avideo
(Composer)
Apr 4, 2026
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-3571
was published
Apr 4, 2026
AVideo: Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php
Moderate
CVE-2026-35179
was published
for
wwbn/avideo
(Composer)
Apr 3, 2026
Signal K Server: Privilege Escalation by Admin Role Injection via /enableSecurity
Critical
CVE-2026-33950
was published
for
signalk-server
(npm)
Apr 3, 2026
Insufficient authentication security controls in the browser-based authentication components in...
Critical
Unreviewed
CVE-2026-35561
was published
Apr 3, 2026
prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due...
High
Unreviewed
CVE-2026-22663
was published
Apr 3, 2026
Ajenti has an authorization bypass during custom package installation
High
CVE-2026-35175
was published
for
ajenti-panel
(pip)
Apr 3, 2026
OpenClaw: Discord voice ingress authorization can be bypassed via channel, name, and stale-role validation gaps
Low
GHSA-x2m8-53h4-6hch
was published
for
openclaw
(npm)
Apr 3, 2026
Electron: USB device selection not validated against filtered device list
Low
CVE-2026-34766
was published
for
electron
(npm)
Apr 3, 2026
OpenClaw: Unauthenticated plugin-auth HTTP routes receive operator runtime scopes
Moderate
GHSA-mhgq-xpfq-6r66
was published
for
openclaw
(npm)
Apr 2, 2026
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
Critical
CVE-2026-34976
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 2, 2026
openssl-encrypt has no owner verification on key revocation — any client can revoke any key
Moderate
GHSA-hvc7-763r-4f3h
was published
for
openssl-encrypt
(pip)
Apr 1, 2026
AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug
Moderate
CVE-2026-34737
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
High
Unreviewed
CVE-2026-20155
was published
Apr 1, 2026
Improper access control in the users MFA feature in Devolutions Server allows an authenticated...
Moderate
Unreviewed
CVE-2026-4925
was published
Apr 1, 2026
Improper access control in the multi-factor authentication (MFA) management API in Devolutions...
Moderate
Unreviewed
CVE-2026-5175
was published
Apr 1, 2026
Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows...
Unknown
Unreviewed
CVE-2025-1249
was published
Apr 1, 2026
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-3831
was published
Apr 1, 2026
OpenClaw's Discord component interaction ingress skips guild/channel policy enforcement
Moderate
GHSA-jp4j-q5fc-58gv
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials
High
GHSA-3cw3-5vxw-g2h3
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Zalo channel downloads media before sender authorization
Moderate
CVE-2026-33576
was published
for
openclaw
(npm)
Mar 31, 2026
AVideo vulnerable to Mass User PII Disclosure via Missing Authorization in YPTWallet users.json.php
Moderate
CVE-2026-34395
was published
for
wwbn/avideo
(Composer)
Mar 31, 2026
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-1797
was published
Mar 31, 2026
ProTip!
Advisories are also available from the
GraphQL API