GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
95 advisories
Filter by severity
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a...
Moderate
Unreviewed
CVE-2026-0299
was published
Aug 13, 2026
Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version...
Moderate
Unreviewed
CVE-2026-32791
was published
Aug 11, 2026
Untrusted search path for some Battery Life Diagnostic Tool software before version 2.9.0 within...
Moderate
Unreviewed
CVE-2026-20799
was published
Aug 11, 2026
A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown...
Moderate
Unreviewed
CVE-2026-18605
was published
Aug 3, 2026
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
Moderate
CVE-2026-45792
was published
for
rtk
(Rust)
May 20, 2026
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security...
Moderate
Unreviewed
CVE-2026-57097
was published
Jul 14, 2026
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app...
Moderate
Unreviewed
CVE-2026-0251
was published
May 13, 2026
A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue...
Moderate
Unreviewed
CVE-2026-15515
was published
Jul 13, 2026
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges...
Moderate
Unreviewed
CVE-2026-42830
was published
May 12, 2026
A flaw was found in the OpenShift Container Platform build system. A user with the `edit`...
Moderate
Unreviewed
CVE-2026-7309
was published
Apr 28, 2026
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
Moderate
CVE-2026-35603
was published
for
@anthropic-ai/claude-code
(npm)
Apr 17, 2026
Perl threads have a working directory race condition where file operations may target unintended...
Moderate
Unreviewed
CVE-2025-40909
was published
May 30, 2025
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3,...
Moderate
Unreviewed
CVE-2012-1854
was published
May 14, 2022
OpenClaw: macOS optional allowlist basename matching could bypass path-based policy
Moderate
CVE-2026-32016
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's tools.exec.safeBins trusted PATH directories allowed binary shadowing in allowlist mode
Moderate
GHSA-qhrr-grqp-6x2g
was published
for
openclaw
(npm)
Mar 3, 2026
IBM App Connect Enterprise Certified Container up to 12.19.0 (Continuous Delivery) and 12.0 LTS ...
Moderate
Unreviewed
CVE-2025-13491
was published
Feb 5, 2026
pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
Moderate
CVE-2026-23888
was published
for
pnpm
(npm)
Jan 26, 2026
Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to...
Moderate
Unreviewed
CVE-2025-49642
was published
Dec 1, 2025
The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to...
Moderate
Unreviewed
CVE-2025-43079
was published
Nov 10, 2025
Apache Tomcat installer for Windows has an untrusted search path vulnerability
Moderate
CVE-2025-49124
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jun 16, 2025
Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated...
Moderate
Unreviewed
CVE-2025-49456
was published
Aug 13, 2025
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier...
Moderate
Unreviewed
CVE-2020-9673
was published
May 24, 2022
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier...
Moderate
Unreviewed
CVE-2020-9672
was published
May 24, 2022
Untrusted search path vulnerability in the pthread_win32_process_attach_np function in pthreadGC2...
Moderate
Unreviewed
CVE-2010-5250
was published
May 17, 2022
Untrusted search path vulnerability in Explzh 5.67 and earlier allows local users to gain...
Moderate
Unreviewed
CVE-2010-3159
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API