GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
55
GitHub Actions
50
Go
3,722
Maven
5,000+
npm
5,000+
NuGet
935
pip
4,944
Pub
13
RubyGems
1,055
Rust
1,338
Swift
54
Unreviewed advisories
All unreviewed
5,000+
4,088 advisories
Filter by severity
NornicDB has Improper Network Binding in its Bolt Server, allowing unauthorized remote access
Critical
CVE-2026-42072
was published
for
github.com/orneryd/nornicdb
(Go)
Apr 22, 2026
nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
Critical
CVE-2026-33471
was published
for
nimiq-block
(Rust)
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
CVE-2026-41203
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
CVE-2026-41202
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 22, 2026
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
Critical
CVE-2026-41179
was published
for
github.com/rclone/rclone
(Go)
Apr 22, 2026
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
Critical
CVE-2026-41176
was published
for
github.com/rclone/rclone
(Go)
Apr 22, 2026
openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access
Critical
CVE-2026-41070
was published
for
github.com/jkroepke/openvpn-auth-oauth2
(Go)
Apr 22, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-41264
was published
for
flowise
(npm)
Apr 21, 2026
Brillig: Heap corruption in foreign call results with nested tuple arrays
Critical
CVE-2026-41197
was published
for
brillig
(Rust)
Apr 21, 2026
Spinnaker: RCE via expression parsing due to unrestricted context handling
Critical
CVE-2026-32613
was published
for
io.spinnaker.echo:echo-pipelinetriggers
(Maven)
Apr 21, 2026
Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
Critical
CVE-2026-32604
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo
(Maven)
Apr 21, 2026
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
Critical
CVE-2026-33557
was published
for
org.apache.kafka:kafka-clients
(Maven)
Apr 20, 2026
Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling
Critical
CVE-2026-41583
was published
for
zebra-script
(Rust)
Apr 18, 2026
Zebra has rk Identity Point Panic in Transaction Verification
Critical
CVE-2026-41584
was published
for
zebra-chain
(Rust)
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
Critical
CVE-2026-41589
was published
for
charm.land/wish/v2
(Go)
Apr 18, 2026
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
Critical
CVE-2026-41574
was published
for
github.com/nhost/nhost
(Go)
Apr 18, 2026
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
Critical
CVE-2026-41265
was published
for
flowise
(npm)
Apr 18, 2026
OpenClaw: Feishu webhook and card-action validation now fail closed
Critical
GHSA-xh72-v6v9-mwhc
was published
for
openclaw
(npm)
Apr 17, 2026
Remote Code Execution (RCE) via String Literal Injection into math-codegen
Critical
CVE-2026-41507
was published
for
math-codegen
(npm)
Apr 17, 2026
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
Critical
CVE-2026-41497
was published
for
praisonai
(pip)
Apr 17, 2026
OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
Critical
CVE-2026-40525
was published
for
openviking
(pip)
Apr 17, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
Critical
CVE-2026-27197
was published
for
sentry
(pip)
Apr 17, 2026
Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
Critical
CVE-2026-23500
was published
for
dolibarr/dolibarr
(Composer)
Apr 17, 2026
Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)
Critical
CVE-2026-41478
was published
for
@saltcorn/server
(npm)
Apr 16, 2026
Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise
Critical
GHSA-3xx2-mqjm-hg9x
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API