GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
356 advisories
Filter by severity
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service...
High
Unreviewed
CVE-2025-71215
was published
May 21, 2026
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism...
High
Unreviewed
CVE-2025-71216
was published
May 21, 2026
A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker...
High
Unreviewed
CVE-2026-45208
was published
May 21, 2026
Undefined behavior may result due to a race condition leading to a use-after-free violation. If...
High
Unreviewed
CVE-2026-5947
was published
May 20, 2026
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in...
High
Unreviewed
CVE-2026-29518
was published
May 20, 2026
Diffusers: TOCTOU Trust Remote Code Bypass
High
CVE-2026-45804
was published
for
diffusers
(pip)
May 20, 2026
Docker: Race condition in docker cp allows bind mount redirection to host path
High
CVE-2026-42306
was published
for
github.com/docker/docker
(Go)
May 18, 2026
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an...
High
Unreviewed
CVE-2026-41702
was published
May 15, 2026
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-35418
was published
May 12, 2026
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU...
High
Unreviewed
CVE-2026-34354
was published
May 8, 2026
n8n-mcp webhook and API client paths has an authenticated SSRF
High
CVE-2026-44694
was published
for
n8n-mcp
(npm)
May 8, 2026
The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver...
High
Unreviewed
CVE-2022-26522
was published
May 8, 2026
Spring Cloud Config Server Susceptible To TOCTOU Attack
High
CVE-2026-41002
was published
for
org.springframework.cloud:spring-cloud-config-server
(Maven)
May 7, 2026
Improper privilege management in the log rotation mechanism of the Skylight Workspace Config...
High
Unreviewed
CVE-2026-7791
was published
May 5, 2026
Memory corruption while creating a process on the digital signal processor due to allocation...
High
Unreviewed
CVE-2025-47407
was published
May 4, 2026
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: defer tunnel...
High
Unreviewed
CVE-2026-31678
was published
Apr 25, 2026
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition
High
CVE-2026-35352
was published
for
coreutils
(Rust)
Apr 22, 2026
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
High
CVE-2026-41272
was published
for
flowise
(npm)
Apr 16, 2026
Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker...
High
Unreviewed
CVE-2026-27929
was published
Apr 14, 2026
A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows...
High
Unreviewed
CVE-2026-30332
was published
Apr 2, 2026
ONNX: TOCTOU arbitrary file read/write in save_external_dat
High
GHSA-q56x-g2fj-4rj6
was published
for
onnx
(pip)
Apr 1, 2026
Duplicate Advisory: OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity
High
GHSA-wmgj-hrx3-23gj
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
The Intel EPT paging code uses an optimization to defer flushing of any cached
EPT state until...
High
Unreviewed
CVE-2026-23554
was published
Mar 23, 2026
OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
High
GHSA-mj4p-rc52-m843
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity
High
CVE-2026-32979
was published
for
openclaw
(npm)
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API