Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
598195
AlmaLinux
4555
Alpaquita
8611
Alpine
4001
Android
3260
BellSoft Hardened Containers
397
Bitnami
6752
Chainguard
5293
CleanStart
428
CRAN
14
crates.io
2147
Debian
53524
Echo
3057
GHC
3
GIT
79667
GitHub Actions
47
Go
6276
Hackage
29
Hex
53
Julia
342
Linux
15364
Mageia
5843
Maven
6241
MinimOS
18274
npm
216473
NuGet
1619
opam
11
openEuler
6219
openSUSE
12240
OSS-Fuzz
3807
Packagist
5887
Pub
10
PyPI
18290
Red Hat
18953
Rocky Linux
2824
Root
10902
RubyGems
1905
SUSE
19969
SwiftURL
48
Ubuntu
51517
VSCode
18
Wolfi
3325
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-4hmj-39m8-jwc7
npm/openclaw
OpenClaw has ACP CLI approval prompt ANSI escape sequence injection
1 hour ago
Fix available
GHSA-j4c9-w69r-cw33
npm/openclaw
OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State
1 hour ago
Fix available
GHSA-mf5g-6r6f-ghhm
npm/openclaw
OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token
1 hour ago
Fix available
GHSA-rf6h-5gpw-qrgq
npm/openclaw
OpenClaw: MS Teams Feedback Invocation Bypasses Sender Allowlists and Records Unauthorized Session Feedback
1 hour ago
Fix available
GHSA-h4jx-hjr3-fhgc
npm/openclaw
OpenClaw: Gateway Plugin Subagent Fallback
`
deleteSession
`
Uses Synthetic
`
operator.admin
`
1 hour ago
Fix available
GHSA-77w2-crqv-cmv3
npm/openclaw
OpenClaw: Feishu Raw Card Send Surface Can Mint Legacy Card Callbacks That Bypass DM Pairing
1 hour ago
Fix available
GHSA-3h52-cx59-c456
npm/openclaw
OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
1 hour ago
Fix available
GHSA-rhfg-j8jq-7v2h
npm/openclaw
OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476)
1 hour ago
Fix available
GHSA-52q4-3xjc-6778
npm/openclaw
OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName
1 hour ago
Fix available
GHSA-q2qc-744p-66r2
npm/openclaw
OpenClaw:
`
session_status
`
sessionId resolution bypasses sandboxed session-tree visibility
1 hour ago
Fix available
GHSA-5jvj-hxmh-6h6j
npm/openclaw
OpenClaw: Gateway HTTP Session History Route Bypasses Operator Read Scope
1 hour ago
No fix available
Severity - 5.3 (Medium)
GHSA-qpfv-44f3-qqx6
npm/@mikro-orm/core
MikroORM has Prototype Pollution in Utils.merge
1 hour ago
Fix available
Severity - 8.3 (High)
GHSA-gwhv-j974-6fxm
npm/@mikro-orm/core
MikroORM is vulnerable to SQL Injection via specially crafted object
1 hour ago
Fix available
Severity - 9.3 (Critical)
GHSA-g3hj-mf85-679g
Packagist/wwbn/avideo
AVideo: IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Live Stream Posters and Trigger False Socket Notifications
1 hour ago
No fix available
Severity - 5.4 (Medium)
GHSA-2rm7-j397-3fqg
Packagist/wwbn/avideo
AVideo: Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast Hijacking
1 hour ago
No fix available
Severity - 6.3 (Medium)
GHSA-wprj-9cvc-5w37
Packagist/wwbn/avideo
AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
1 hour ago
No fix available
Severity - 7.5 (High)
Load more...
Vulnerability Database - OSV