GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,176 advisories
Filter by severity
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
Moderate
CVE-2026-73557
was published
for
vllm
(pip)
Sep 4, 2026
A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the...
Moderate
Unreviewed
CVE-2026-82543
was published
Aug 30, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
Moderate
Unreviewed
CVE-2026-58616
was published
Aug 28, 2026
SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows...
Moderate
Unreviewed
CVE-2026-82258
was published
Aug 28, 2026
A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR...
Moderate
Unreviewed
CVE-2026-59321
was published
Aug 27, 2026
Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a...
Moderate
Unreviewed
CVE-2026-79117
was published
Aug 25, 2026
Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-79094
was published
Aug 25, 2026
Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who...
Moderate
Unreviewed
CVE-2026-79014
was published
Aug 25, 2026
Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-78979
was published
Aug 25, 2026
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
Moderate
GHSA-mc9m-6fm9-pghc
was published
for
kcl-lib
(pip)
Aug 20, 2026
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
Moderate
CVE-2026-45404
was published
for
go.opentelemetry.io/otel/bridge/opentracing
(Go)
Aug 20, 2026
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can...
Moderate
Unreviewed
CVE-2025-62300
was published
Aug 20, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model...
Moderate
Unreviewed
CVE-2026-76393
was published
Aug 20, 2026
Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154...
Moderate
Unreviewed
CVE-2026-74984
was published
Aug 18, 2026
Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox...
Moderate
Unreviewed
CVE-2026-74973
was published
Aug 18, 2026
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login...
Moderate
Unreviewed
CVE-2026-1199
was published
Aug 18, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
Moderate
CVE-2026-64865
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with...
Moderate
Unreviewed
CVE-2026-13198
was published
Aug 14, 2026
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally...
Moderate
Unreviewed
CVE-2026-0295
was published
Aug 13, 2026
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0...
Moderate
Unreviewed
CVE-2026-7366
was published
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2026-18150
was published
Aug 12, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2026-18250
was published
Aug 12, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
Moderate
Unreviewed
CVE-2026-61920
was published
Aug 11, 2026
A denial-of-service
vulnerability exists in httpd service on Archer A6 v4 where the asynchronous...
Moderate
Unreviewed
CVE-2026-9030
was published
Aug 7, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition...
Moderate
Unreviewed
CVE-2026-47620
was published
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API