GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
50 advisories
Filter by severity
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the...
Critical
Unreviewed
CVE-2026-43631
was published
Aug 7, 2026
Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had...
Critical
Unreviewed
CVE-2026-17855
was published
Jul 30, 2026
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who...
Critical
Unreviewed
CVE-2026-17709
was published
Jul 30, 2026
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who...
Critical
Unreviewed
CVE-2026-17711
was published
Jul 30, 2026
Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfaul1 ESP32-audioI2S 3.4.5...
Critical
Unreviewed
CVE-2026-51261
was published
Jul 28, 2026
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and...
Critical
Unreviewed
CVE-2026-64720
was published
Jul 27, 2026
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and...
Critical
Unreviewed
CVE-2026-43805
was published
Jul 27, 2026
A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8...
Critical
Unreviewed
CVE-2026-28982
was published
Jul 27, 2026
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP ...
Critical
Unreviewed
CVE-2026-63756
was published
Jul 20, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
Critical
Unreviewed
CVE-2026-56188
was published
Jul 14, 2026
Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised...
Critical
Unreviewed
CVE-2026-13882
was published
Jul 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: fix racing...
Critical
Unreviewed
CVE-2026-53086
was published
Jun 24, 2026
In createSessionInternal of PackageInstallerService.java, there is a possible method to remove a...
Critical
Unreviewed
CVE-2026-0068
was published
Jun 17, 2026
In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition....
Critical
Unreviewed
CVE-2026-0083
was published
Jun 17, 2026
An authentication
bypass security issue exists within FactoryTalk Historian Site Edition. By...
Critical
Unreviewed
CVE-2025-13036
was published
Jun 16, 2026
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1,...
Critical
Unreviewed
CVE-2025-10263
was published
Jun 9, 2026
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: ADD_ADDR rtx: fix...
Critical
Unreviewed
CVE-2026-46137
was published
May 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: fix race between...
Critical
Unreviewed
CVE-2026-46135
was published
May 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix potential race in...
Critical
Unreviewed
CVE-2026-43198
was published
May 6, 2026
Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who...
Critical
Unreviewed
CVE-2026-5902
was published
Apr 9, 2026
In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in...
Critical
Unreviewed
CVE-2025-32991
was published
Mar 25, 2026
Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance
Critical
CVE-2026-32242
was published
for
parse-server
(npm)
Mar 12, 2026
In the Linux kernel, the following vulnerability has been resolved:
tls: Fix race condition in...
Critical
Unreviewed
CVE-2026-23240
was published
Mar 10, 2026
A race condition was addressed with improved handling of symbolic links. This issue is fixed in...
Critical
Unreviewed
CVE-2026-20677
was published
Feb 12, 2026
Eclipse Jersey has a Race Condition
Critical
CVE-2025-12383
was published
for
org.glassfish.jersey.core:jersey-client
(Maven)
Nov 18, 2025
ProTip!
Advisories are also available from the
GraphQL API