GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
708 advisories
Filter by severity
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary...
High
Unreviewed
CVE-2026-16922
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical...
High
Unreviewed
CVE-2026-16838
was published
Aug 19, 2026
Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote...
Moderate
Unreviewed
CVE-2026-73829
was published
Aug 19, 2026
Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of...
High
Unreviewed
CVE-2024-13942
was published
Aug 19, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of...
High
Unreviewed
CVE-2026-16819
was published
Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race...
High
Unreviewed
CVE-2026-56797
was published
Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU)...
High
Unreviewed
CVE-2026-53477
was published
Aug 19, 2026
During execve(2) of a SUID binary, the new virtual address space is installed before the process...
High
Unreviewed
CVE-2026-49415
was published
Aug 19, 2026
Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had...
High
Unreviewed
CVE-2026-76044
was published
Aug 18, 2026
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Moderate
CVE-2026-70667
was published
for
lemur
(pip)
Aug 18, 2026
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the...
High
Unreviewed
CVE-2026-71539
was published
Aug 18, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized...
High
Unreviewed
CVE-2026-16967
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized...
High
Unreviewed
CVE-2026-16896
was published
Aug 13, 2026
Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions...
Moderate
Unreviewed
CVE-2026-20908
was published
Aug 11, 2026
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could...
Moderate
Unreviewed
CVE-2026-6505
was published
Aug 11, 2026
The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could...
Moderate
Unreviewed
CVE-2026-5303
was published
Aug 11, 2026
A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an...
High
Unreviewed
CVE-2026-72584
was published
Aug 10, 2026
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles...
Moderate
Unreviewed
CVE-2026-19079
was published
Aug 7, 2026
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama...
Critical
Unreviewed
CVE-2026-43632
was published
Aug 7, 2026
A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization...
High
Unreviewed
CVE-2026-57818
was published
Aug 6, 2026
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
High
Unreviewed
CVE-2026-71272
was published
Aug 5, 2026
Electron: Parent process code-sign check is spoofable
Moderate
CVE-2026-70597
was published
for
electron
(npm)
Aug 5, 2026
Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target...
Moderate
Unreviewed
CVE-2026-71210
was published
Aug 5, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API