GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
356 advisories
Filter by severity
NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time...
High
Unreviewed
CVE-2026-24260
was published
Jul 1, 2026
Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation...
High
Unreviewed
CVE-2026-57959
was published
Jun 29, 2026
acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition...
High
Unreviewed
CVE-2026-54370
was published
Jun 29, 2026
In the Linux kernel, the following vulnerability has been resolved:
xsk: cache csum_start...
High
Unreviewed
CVE-2026-53250
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
drm/gem: Try to fix...
High
Unreviewed
CVE-2026-53145
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
sched/psi: fix race between...
High
Unreviewed
CVE-2026-52991
was published
Jun 24, 2026
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
High
CVE-2026-54353
was published
for
@budibase/backend-core
(npm)
Jun 22, 2026
A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a...
High
Unreviewed
CVE-2026-41045
was published
Jun 22, 2026
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
High
CVE-2026-57114
was published
for
praisonai
(pip)
Jun 18, 2026
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's...
High
Unreviewed
CVE-2026-54228
was published
Jun 13, 2026
Duplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
High
GHSA-gwcq-453v-2frr
was published
for
openclaw
(npm)
Jun 13, 2026
•
withdrawn
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv...
High
Unreviewed
CVE-2026-53822
was published
Jun 13, 2026
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators
High
GHSA-9wcp-79g5-5c3c
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing
High
CVE-2026-50631
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital...
High
Unreviewed
CVE-2026-24067
was published
Jun 10, 2026
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service...
High
Unreviewed
CVE-2026-45487
was published
Jun 9, 2026
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation...
High
Unreviewed
CVE-2026-24065
was published
Jun 9, 2026
A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0...
High
Unreviewed
CVE-2026-2638
was published
Jun 9, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token
High
CVE-2026-45720
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that...
High
Unreviewed
CVE-2025-41259
was published
Jun 3, 2026
A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13...
High
Unreviewed
CVE-2025-64390
was published
Jun 2, 2026
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input...
High
Unreviewed
CVE-2026-25260
was published
Jun 2, 2026
In the Linux kernel, the following vulnerability has been resolved:
sctp: revalidate list cursor...
High
Unreviewed
CVE-2026-46227
was published
May 28, 2026
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time...
High
Unreviewed
CVE-2026-24191
was published
May 26, 2026
ProTip!
Advisories are also available from the
GraphQL API