GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,730 advisories
Filter by severity
@tinacms/graphql has a Path Traversal issue
Moderate
CVE-2026-24125
was published
for
@tinacms/graphql
(npm)
Mar 12, 2026
Trix has a Stored XSS vulnerability through serialized attributes
Moderate
GHSA-qmpg-8xg6-ph5q
was published
for
action_text-trix
(RubyGems)
Mar 12, 2026
Parse Server has a SQL injection via query field name when using PostgreSQL
Moderate
CVE-2026-32234
was published
for
parse-server
(npm)
Mar 12, 2026
@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint
Moderate
CVE-2026-32237
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Mar 12, 2026
@backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass
Moderate
CVE-2026-32235
was published
for
@backstage/plugin-auth-backend
(npm)
Mar 12, 2026
StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts
Moderate
CVE-2026-32106
was published
for
studiocms
(npm)
Mar 12, 2026
StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's Settings
Moderate
CVE-2026-32104
was published
for
studiocms
(npm)
Mar 12, 2026
StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generation
Moderate
CVE-2026-32103
was published
for
studiocms
(npm)
Mar 12, 2026
Uptime Kuma is Missing Authorization Checks on Ping Badge Endpoint, Leaks Ping times of monitors without needing to be on a status page
Moderate
CVE-2026-32230
was published
for
uptime-kuma
(npm)
Mar 12, 2026
OpenClaw: /api/channels gateway-auth boundary bypass via path canonicalization mismatch
Moderate
GHSA-8j2w-6fmm-m587
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers
Moderate
GHSA-v8cg-4474-49v8
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is empty
Moderate
GHSA-g7cr-9h7q-4qxq
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path
Moderate
GHSA-vhwf-4x96-vqx2
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
GHSA-8g75-q649-6pv6
was published
for
openclaw
(npm)
Mar 12, 2026
Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause
Moderate
CVE-2026-32098
was published
for
parse-server
(npm)
Mar 12, 2026
Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check
Moderate
CVE-2026-31860
was published
for
unhead
(npm)
Mar 12, 2026
devalue has prototype pollution in devalue.parse and devalue.unflatten
Moderate
CVE-2026-30226
was published
for
devalue
(npm)
Mar 12, 2026
Duplicate Advisory: OpenClaw: Skill env override host env injection via applySkillConfigEnvOverrides (defense-in-depth)
Moderate
GHSA-wgx8-r9vw-2w4h
was published
for
openclaw
(npm)
Mar 12, 2026
•
withdrawn
Duplicate Advisory: OpenClaw safeBins file-existence oracle information disclosure
Moderate
GHSA-xjj9-2w6f-jg55
was published
for
openclaw
(npm)
Mar 12, 2026
•
withdrawn
yauzl contains an off-by-one error
Moderate
CVE-2026-31988
was published
for
yauzl
(npm)
Mar 12, 2026
Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash
Moderate
CVE-2026-32094
was published
for
shescape
(npm)
Mar 11, 2026
Parse Server vulnerable to user enumeration via email verification endpoint
Moderate
CVE-2026-31901
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server vulnerable to stored XSS via file upload of HTML-renderable file types
Moderate
CVE-2026-31868
was published
for
parse-server
(npm)
Mar 11, 2026
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
Moderate
GHSA-v8w9-8mx6-g223
was published
for
hono
(npm)
Mar 11, 2026
Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction
Moderate
CVE-2026-31828
was published
for
parse-server
(npm)
Mar 11, 2026
ProTip!
Advisories are also available from the
GraphQL API