GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
456 advisories
Filter by severity
OpenClaw: Zalo webhook rate limiting could be bypassed before secret validation
Moderate
GHSA-5m9r-p9g7-679c
was published
for
openclaw
(npm)
Mar 13, 2026
Anytype Heart's gRPC API client challenge verification can be bypassed on localhost
Low
CVE-2026-31863
was published
for
github.com/anyproto/anytype-cli
(Go)
Mar 11, 2026
An improper restriction of excessive authentication attempts vulnerability in Fortinet...
Low
Unreviewed
CVE-2026-22629
was published
Mar 10, 2026
Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and...
Critical
Unreviewed
CVE-2025-69615
was published
Mar 10, 2026
OneUptime has WhatsApp Resend Verification Authorization Bypass
Moderate
CVE-2026-30959
was published
for
@oneuptime/common
(npm)
Mar 10, 2026
OpenClaw's hooks count non-POST requests toward auth lockout
Moderate
GHSA-6rmx-gvvg-vh6j
was published
for
openclaw
(npm)
Mar 9, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-20882
was published
Mar 6, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-24696
was published
Mar 6, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-27778
was published
Mar 6, 2026
Improper Restriction of Excessive Authentication Attempts, Use of Password Hash With Insufficient...
Critical
Unreviewed
CVE-2026-30790
was published
Mar 5, 2026
Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement
Moderate
CVE-2026-27801
was published
for
vaultwarden
(Rust)
Mar 4, 2026
OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains
Moderate
GHSA-jmmg-jqc7-5qf4
was published
for
openclaw
(npm)
Mar 3, 2026
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a...
Moderate
Unreviewed
CVE-2025-36363
was published
Mar 3, 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass...
Moderate
Unreviewed
CVE-2026-27753
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-24445
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-26305
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-25114
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-25945
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-25113
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-20792
was published
Feb 27, 2026
VideoLAN VLC for Android prior to version 3.7.0 contain an authentication bypass in the Remote...
Moderate
Unreviewed
CVE-2026-26227
was published
Feb 26, 2026
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement...
Moderate
Unreviewed
CVE-2026-27521
was published
Feb 24, 2026
Wildfly Elytron integration susceptible to brute force attacks via CLI
High
CVE-2025-23368
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Feb 13, 2026
A security flaw has been discovered in Tasin1025 SwiftBuy up to...
Moderate
Unreviewed
CVE-2026-2110
was published
Feb 7, 2026
Moodle Affected by Improper Restriction of Excessive Authentication Attempts
High
CVE-2025-67853
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
ProTip!
Advisories are also available from the
GraphQL API