GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,464 advisories
Filter by severity
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent...
High
Unreviewed
CVE-2026-32048
was published
Mar 21, 2026
Apache Airflow: DAG authorization bypass
Moderate
CVE-2026-28563
was published
for
apache-airflow
(pip)
Mar 17, 2026
Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata
High
CVE-2026-26929
was published
for
apache-airflow
(pip)
Mar 17, 2026
Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file...
Moderate
Unreviewed
CVE-2026-29516
was published
Mar 16, 2026
OpenClaw session transcript files were created without forced user-only permissions
Moderate
GHSA-vr7j-g7jv-h5mp
was published
for
openclaw
(npm)
Mar 16, 2026
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
Moderate
CVE-2026-32704
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 13, 2026
An Incorrect
Permission Assignment vulnerability exists in the ASUS Business
System Control...
Moderate
Unreviewed
CVE-2025-15037
was published
Mar 12, 2026
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure ...
High
Unreviewed
CVE-2026-24291
was published
Mar 10, 2026
An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get...
Moderate
Unreviewed
CVE-2025-41712
was published
Mar 10, 2026
Sensitive information disclosure due to improper configuration of a headless browser. The...
Moderate
Unreviewed
CVE-2026-28725
was published
Mar 6, 2026
Credentials are not deleted from Acronis Agent after plan revocation. The following products are...
Moderate
Unreviewed
CVE-2025-30413
was published
Mar 6, 2026
Credentials are not deleted from Acronis Agent after plan revocation. The following products are...
Moderate
Unreviewed
CVE-2025-11790
was published
Mar 6, 2026
IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local...
High
Unreviewed
CVE-2026-29125
was published
Mar 5, 2026
Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in...
High
Unreviewed
CVE-2026-29126
was published
Mar 5, 2026
File Browser's TUS Delete Endpoint Bypasses Delete Permission Check
Critical
CVE-2026-29188
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 4, 2026
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for...
Moderate
Unreviewed
CVE-2025-12801
was published
Mar 4, 2026
erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded...
Moderate
Unreviewed
CVE-2025-70342
was published
Mar 4, 2026
IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0...
Moderate
Unreviewed
CVE-2025-14604
was published
Mar 3, 2026
iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged...
High
Unreviewed
CVE-2026-2637
was published
Mar 3, 2026
An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly...
Critical
Unreviewed
CVE-2026-21902
was published
Feb 25, 2026
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File...
High
Unreviewed
CVE-2026-26096
was published
Feb 20, 2026
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File...
High
Unreviewed
CVE-2026-26101
was published
Feb 20, 2026
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File...
High
Unreviewed
CVE-2026-26102
was published
Feb 20, 2026
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File...
High
Unreviewed
CVE-2026-26095
was published
Feb 20, 2026
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File...
Moderate
Unreviewed
CVE-2026-26100
was published
Feb 20, 2026
ProTip!
Advisories are also available from the
GraphQL API