GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
122 advisories
Filter by severity
A security flaw has been discovered in ramon-victor freegpt-webui up to...
Low
Unreviewed
CVE-2026-85704
was published
Sep 4, 2026
A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects...
Low
Unreviewed
CVE-2026-85639
was published
Sep 4, 2026
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an...
Low
Unreviewed
CVE-2026-82364
was published
Aug 29, 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS...
Low
Unreviewed
CVE-2026-64782
was published
Aug 18, 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS...
Low
Unreviewed
CVE-2026-64779
was published
Aug 18, 2026
A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function...
Low
Unreviewed
CVE-2026-19975
was published
Aug 17, 2026
A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function...
Low
Unreviewed
CVE-2026-16212
was published
Jul 19, 2026
A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function...
Low
Unreviewed
CVE-2026-16208
was published
Jul 19, 2026
A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This...
Low
Unreviewed
CVE-2026-16211
was published
Jul 19, 2026
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the...
Low
Unreviewed
CVE-2026-16082
was published
Jul 18, 2026
mkdir: -m exposes directory with umask perms before chmod (race window)
Low
CVE-2026-35353
was published
for
uu_mkdir
(Rust)
Jul 6, 2026
A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream...
Low
Unreviewed
CVE-2026-13502
was published
Jun 28, 2026
A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function...
Low
Unreviewed
CVE-2026-10565
was published
Jun 2, 2026
Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to...
Low
Unreviewed
CVE-2026-9959
was published
May 29, 2026
A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file...
Low
Unreviewed
CVE-2026-8741
was published
May 17, 2026
Race in Shared Storage in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had...
Low
Unreviewed
CVE-2026-7954
was published
May 6, 2026
parse-server: MFA SMS one-time password accepted twice under concurrent login
Low
CVE-2026-43930
was published
for
parse-server
(npm)
May 5, 2026
Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
Low
CVE-2026-7846
was published
for
langchain-chatchat
(pip)
May 5, 2026
Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
Low
CVE-2026-7724
was published
for
prefect
(pip)
May 4, 2026
Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user...
Low
Unreviewed
CVE-2026-7351
was published
Apr 29, 2026
UAF vulnerability in the screen management module.
Impact: Successful exploitation of this...
Low
Unreviewed
CVE-2026-34849
was published
Apr 13, 2026
Race condition vulnerability in the event notification module.
Impact: Successful exploitation of...
Low
Unreviewed
CVE-2026-34851
was published
Apr 13, 2026
Race condition vulnerability in the notification service.
Impact: Successful exploitation of this...
Low
Unreviewed
CVE-2026-34850
was published
Apr 13, 2026
OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths
Low
CVE-2026-41913
was published
for
openclaw
(npm)
Apr 9, 2026
In VPU, there is a possible use-after-free read due to a race condition. This could lead to local...
Low
Unreviewed
CVE-2026-0121
was published
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API