GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,148
Maven
5,000+
npm
5,000+
NuGet
859
pip
4,444
Pub
12
RubyGems
990
Rust
1,176
Swift
50
Unreviewed advisories
All unreviewed
5,000+
120,570 advisories
Filter by severity
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
High
Unreviewed
CVE-2026-21670
was published
Mar 12, 2026
A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function...
High
Unreviewed
CVE-2026-4041
was published
Mar 12, 2026
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate...
High
Unreviewed
CVE-2026-21668
was published
Mar 12, 2026
A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function...
High
Unreviewed
CVE-2026-4042
was published
Mar 12, 2026
In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an...
High
Unreviewed
CVE-2026-2514
was published
Mar 12, 2026
A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an...
High
Unreviewed
CVE-2026-2513
was published
Mar 12, 2026
StudioCMS S3 Storage Manager Authorization Bypass via Missing `await` on Async Auth Check
High
CVE-2026-32101
was published
for
@studiocms/s3-storage
(npm)
Mar 12, 2026
Traefik: HTTP/2 frames can cause a running server to panic
High
GHSA-4hjq-9h5c-252j
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 12, 2026
SiYuan has a Full-Read SSRF via /api/network/forwardProxy
High
CVE-2026-32110
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 12, 2026
OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary
High
GHSA-qcc4-p59m-p54m
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf
High
GHSA-mgrq-9f93-wpp5
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: LINE group allowlist scope mismatch with DM pairing-store entries
High
GHSA-gp3q-wpq4-5c5h
was published
for
openclaw
(npm)
Mar 12, 2026
OliveTin Vulnerable to Unauthorized Action Output Disclosure via EventStream
High
CVE-2026-32102
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
Tornado is vulnerable to DoS due to too many multipart parts
High
CVE-2026-31958
was published
for
tornado
(pip)
Mar 12, 2026
Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check
High
CVE-2026-31860
was published
for
unhead
(npm)
Mar 12, 2026
ImageMagick has stack buffer overflow in MagnifyImage
High
CVE-2026-30929
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick: Integer overflow in DIB coder can result in out of bounds read or write
High
CVE-2026-28693
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick has uninitialized pointer dereference in JBIG decoder
High
CVE-2026-28691
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays
High
CVE-2026-28494
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick: MSL attribute stack buffer overflow leads to out of bounds write.
High
CVE-2026-25968
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code...
High
Unreviewed
CVE-2026-4007
was published
Mar 12, 2026
A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of...
High
Unreviewed
CVE-2026-4008
was published
Mar 12, 2026
A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function...
High
Unreviewed
CVE-2026-3978
was published
Mar 12, 2026
A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function...
High
Unreviewed
CVE-2026-3975
was published
Mar 12, 2026
The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the ...
High
Unreviewed
CVE-2026-3657
was published
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API