GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,471 advisories
Filter by severity
Briefcase: Windows MSI Installer Privilege Escalation via Insecure Directory Permissions
High
CVE-2026-33430
was published
for
briefcase
(pip)
Mar 23, 2026
OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns
Moderate
CVE-2026-32048
was published
for
openclaw
(npm)
Mar 2, 2026
Duplicate Advisory: OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns
High
GHSA-wr92-6w3g-2hwc
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate...
High
Unreviewed
CVE-2026-34352
was published
Mar 27, 2026
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11...
Moderate
Unreviewed
CVE-2026-3113
was published
Mar 26, 2026
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as...
High
Unreviewed
CVE-2009-0115
was published
May 2, 2022
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2026-20693
was published
Mar 25, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-28829
was published
Mar 25, 2026
When
a certificate and its private key are installed in the Windows machine
certificate store...
Low
Unreviewed
CVE-2026-4761
was published
Mar 25, 2026
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for...
Moderate
Unreviewed
CVE-2025-12801
was published
Mar 4, 2026
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform...
Critical
Unreviewed
CVE-2024-21915
was published
Feb 16, 2024
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for...
Low
Unreviewed
CVE-2005-4868
was published
May 1, 2022
TrustPort Antivirus before 2.8.0.2266 and PC Security before 2.0.0.1291 use weak permissions ...
Moderate
Unreviewed
CVE-2009-3482
was published
May 2, 2022
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which...
Moderate
Unreviewed
CVE-2009-1073
was published
May 2, 2022
IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7...
Moderate
Unreviewed
CVE-2007-5544
was published
May 1, 2022
Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure ...
High
Unreviewed
CVE-2026-24291
was published
Mar 10, 2026
Apache Airflow: DAG authorization bypass
Moderate
CVE-2026-28563
was published
for
apache-airflow
(pip)
Mar 17, 2026
Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata
High
CVE-2026-26929
was published
for
apache-airflow
(pip)
Mar 17, 2026
Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file...
Moderate
Unreviewed
CVE-2026-29516
was published
Mar 16, 2026
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
Moderate
CVE-2026-32704
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 13, 2026
OpenClaw session transcript files were created without forced user-only permissions
Moderate
GHSA-vr7j-g7jv-h5mp
was published
for
openclaw
(npm)
Mar 16, 2026
A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not...
High
Unreviewed
CVE-2010-0737
was published
Apr 21, 2022
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure...
Moderate
Unreviewed
CVE-2009-3489
was published
May 2, 2022
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of...
Moderate
Unreviewed
CVE-2009-3289
was published
May 2, 2022
An Incorrect
Permission Assignment vulnerability exists in the ASUS Business
System Control...
Moderate
Unreviewed
CVE-2025-15037
was published
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API