GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,437
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,695
Pub
13
RubyGems
1,031
Rust
1,222
Swift
53
Unreviewed advisories
All unreviewed
5,000+
597 advisories
Filter by severity
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
High
CVE-2026-39883
was published
for
go.opentelemetry.io/otel/sdk
(Go)
Apr 8, 2026
OpenClaw Has Incomplete Fix for CVE-2026-4039: CLI Backend Environment Variable Injection via Workspace Config
High
GHSA-vfw7-6rhc-6xxg
was published
for
openclaw
(npm)
Apr 7, 2026
Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0...
Critical
Unreviewed
CVE-2025-39666
was published
Apr 7, 2026
Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a...
High
Unreviewed
CVE-2022-4987
was published
Apr 3, 2026
The application's installer runs with elevated privileges but resolves system executables and...
High
Unreviewed
CVE-2026-3780
was published
Apr 1, 2026
OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover
Critical
GHSA-8rh7-6779-cjqq
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw has an Arbitrary Malicious Code Execution Vulnerability
High
GHSA-m3mh-3mpg-37hw
was published
for
openclaw
(npm)
Mar 30, 2026
A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some...
High
Unreviewed
CVE-2026-4962
was published
Mar 27, 2026
A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function...
High
Unreviewed
CVE-2026-4546
was published
Mar 22, 2026
A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown...
High
Unreviewed
CVE-2026-4545
was published
Mar 22, 2026
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path...
High
Unreviewed
CVE-2026-21333
was published
Mar 11, 2026
Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2026-25190
was published
Mar 10, 2026
A weakness has been identified in UltraVNC 1.6.4.0 on Windows. This affects an unknown function...
High
Unreviewed
CVE-2026-3787
was published
Mar 9, 2026
OpenClaw's `tools.exec.safeBins` PATH-hijack allowed trojan binaries to bypass allowlist checks
High
CVE-2026-32015
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: safeBins static default trusted dirs allow writable-dir binary hijack (`jq`)
High
CVE-2026-32009
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's shell env fallback trusts unvalidated SHELL path from host environment
High
CVE-2026-32032
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's tools.exec.safeBins trusted PATH directories allowed binary shadowing in allowlist mode
Moderate
GHSA-qhrr-grqp-6x2g
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: macOS optional allowlist basename matching could bypass path-based policy
Moderate
CVE-2026-32016
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind
High
CVE-2026-31997
was published
for
openclaw
(npm)
Mar 2, 2026
ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local...
High
Unreviewed
CVE-2026-2998
was published
Feb 23, 2026
A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25....
High
Unreviewed
CVE-2026-2538
was published
Feb 16, 2026
A weakness has been identified in Total VPN 0.5.29.0 on Windows. Affected by this vulnerability...
High
Unreviewed
CVE-2026-2542
was published
Feb 16, 2026
A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4 on 32-bit...
High
Unreviewed
CVE-2026-2516
was published
Feb 15, 2026
A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the...
High
Unreviewed
CVE-2025-15569
was published
Feb 10, 2026
Tanium addressed an improper input validation vulnerability in Tanium Appliance.
Low
Unreviewed
CVE-2025-15321
was published
Feb 5, 2026
ProTip!
Advisories are also available from the
GraphQL API