GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,436
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,694
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
13,697 advisories
Filter by severity
OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets
Low
GHSA-fqrj-m88p-qf3v
was published
for
openclaw
(npm)
Apr 7, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18...
Low
Unreviewed
CVE-2026-4916
was published
Apr 9, 2026
The WP Fastest Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
Low
Unreviewed
CVE-2025-10583
was published
Dec 12, 2025
The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized...
Low
Unreviewed
CVE-2025-12958
was published
Jan 7, 2026
The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to...
Low
Unreviewed
CVE-2023-1430
was published
Jun 9, 2023
The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is...
Low
Unreviewed
CVE-2024-3073
was published
Jun 13, 2024
The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up...
Low
Unreviewed
CVE-2024-3034
was published
Apr 27, 2024
Apache Cassandra has an authenticated DoS over CQL
Low
CVE-2026-32588
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Apr 7, 2026
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup...
Low
Unreviewed
CVE-2025-10306
was published
Oct 3, 2025
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination...
Low
Unreviewed
CVE-2023-5775
was published
Feb 26, 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial...
Low
Unreviewed
CVE-2024-6434
was published
Jul 4, 2024
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to...
Low
Unreviewed
CVE-2023-6160
was published
Nov 22, 2023
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode...
Low
Unreviewed
CVE-2024-1075
was published
Feb 6, 2024
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress...
Low
Unreviewed
CVE-2023-6164
was published
Nov 22, 2023
Django vulnerable to privilege abuse in ModelAdmin.list_editable
Low
CVE-2026-4292
was published
for
Django
(pip)
Apr 7, 2026
Django vulnerable to privilege abuse in GenericInlineModelAdmin
Low
CVE-2026-4277
was published
for
Django
(pip)
Apr 7, 2026
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
Low
CVE-2026-34166
was published
for
liquidjs
(npm)
Apr 8, 2026
Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission...
Low
Unreviewed
CVE-2026-28264
was published
Apr 8, 2026
Electron: Crash in clipboard.readImage() on malformed clipboard image data
Low
CVE-2026-34781
was published
for
electron
(npm)
Apr 7, 2026
Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim
Low
CVE-2026-37977
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 6, 2026
PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py
Low
CVE-2026-5559
was published
for
pyblade
(pip)
Apr 5, 2026
justhtml: Mutation XSS with custom foreign-namespace sanitization policies
Low
GHSA-r758-8hxw-4845
was published
for
justhtml
(pip)
Apr 8, 2026
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid...
Low
Unreviewed
CVE-2025-67806
was published
Apr 1, 2026
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Low
Unreviewed
CVE-2026-3479
was published
Mar 18, 2026
OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send
Low
GHSA-767m-xrhc-fxm7
was published
for
openclaw
(npm)
Apr 7, 2026
ProTip!
Advisories are also available from the
GraphQL API