GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
912
pip
4,768
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
48 advisories
Filter by severity
paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
Critical
GHSA-68qg-g8mg-6pr7
was published
for
@paperclipai/server
(npm)
Apr 10, 2026
openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools
Moderate
CVE-2026-39398
was published
for
openclaw-claude-bridge
(npm)
Apr 8, 2026
Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist
Critical
CVE-2026-31818
was published
for
@budibase/backend-core
(npm)
Apr 3, 2026
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
High
CVE-2026-34780
was published
for
electron
(npm)
Apr 3, 2026
DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost
High
CVE-2026-34742
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Apr 1, 2026
Duplicate Advisory: OpenClaw has an improper sandbox configuration vulnerability
Moderate
GHSA-q94v-v6m9-jhq9
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
@siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection
High
CVE-2026-31975
was published
for
@siteboon/claude-code-ui
(npm)
Mar 11, 2026
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
Critical
CVE-2026-26190
was published
for
github.com/milvus-io/milvus
(Go)
Feb 11, 2026
FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
Critical
CVE-2026-25894
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA contains an insecure default configuration vulnerability
High
CVE-2025-69970
was published
for
fuxa-server
(npm)
Feb 3, 2026
terraform-provider-proxmox has insecure sudo recommendation in the documentation
High
CVE-2026-25499
was published
for
github.com/bpg/terraform-provider-proxmox
(Go)
Feb 2, 2026
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
Critical
CVE-2025-62877
was published
for
github.com/harvester/harvester-installer
(Go)
Jan 5, 2026
Misskey has a login rate limit bypass via spoofed X-Forwarded-For header
Moderate
CVE-2025-66482
was published
for
misskey-js
(npm)
Dec 15, 2025
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
High
CVE-2025-66416
was published
for
mcp
(pip)
Dec 2, 2025
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
High
CVE-2025-66414
was published
for
@modelcontextprotocol/sdk
(npm)
Dec 2, 2025
Ray's New Token Authentication is Disabled By Default
Critical
CVE-2025-34351
was published
for
ray
(pip)
Nov 27, 2025
Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by default
High
CVE-2025-13357
was published
for
github.com/hashicorp/terraform-provider-vault
(Go)
Nov 21, 2025
Jenkins Eggplant Runner Plugin protection mechanism disabled
Moderate
CVE-2025-64135
was published
for
io.jenkins.plugins:eggplant-runner
(Maven)
Oct 29, 2025
Liferay has Insecure Default Initialization of Resource issue
Moderate
CVE-2025-43797
was published
for
com.liferay:com.liferay.site.admin.web
(Maven)
Sep 16, 2025
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Critical
CVE-2025-54127
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
Moderate
CVE-2025-53602
was published
for
io.zipkin:zipkin-server
(Maven)
Jul 4, 2025
CNCF K3s Kubernetes kubelet configuration exposes credentials
Moderate
CVE-2025-46599
was published
for
github.com/k3s-io/k3s
(Go)
Apr 25, 2025
Shopware default newsletter opt-in settings allow for mass sign-up abuse
Low
CVE-2025-32378
was published
for
shopware/core
(Composer)
Apr 9, 2025
Filament has exported files stored in default (`public`) filesystem if not reconfigured
Low
CVE-2024-51758
was published
for
filament/actions
(Composer)
Nov 7, 2024
Insecure Default Initialization of Resource vulnerability in Apache Solr
High
CVE-2024-45217
was published
for
org.apache.solr:solr
(Maven)
Oct 16, 2024
ProTip!
Advisories are also available from the
GraphQL API