GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
2,339 advisories
Filter by severity
hono/jsx does not isolate context per request, leading to cross-request data disclosure
Moderate
CVE-2026-59896
was published
for
hono
(npm)
Jul 21, 2026
In the Linux kernel, the following vulnerability has been resolved:
quota: Fix race of...
High
Unreviewed
CVE-2026-53050
was published
Jun 24, 2026
NocoDB: OAuth Authorization Code Race Condition
Moderate
CVE-2026-47386
was published
for
nocodb
(npm)
Jun 5, 2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
High
CVE-2026-53518
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
Moderate
CVE-2026-47703
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Jun 4, 2026
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-50369
was published
Jul 14, 2026
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP ...
Critical
Unreviewed
CVE-2026-63756
was published
Jul 20, 2026
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix potential race in...
Critical
Unreviewed
CVE-2026-43198
was published
May 6, 2026
A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function...
Low
Unreviewed
CVE-2026-16212
was published
Jul 19, 2026
A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This...
Low
Unreviewed
CVE-2026-16211
was published
Jul 19, 2026
A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function...
Low
Unreviewed
CVE-2026-16208
was published
Jul 19, 2026
In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Fix race...
High
Unreviewed
CVE-2026-45945
was published
May 27, 2026
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the...
Low
Unreviewed
CVE-2026-16082
was published
Jul 18, 2026
IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an...
Moderate
Unreviewed
CVE-2026-15995
was published
Jul 17, 2026
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment ...
High
Unreviewed
CVE-2026-51082
was published
Jul 17, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2026-58598
was published
Jul 17, 2026
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-50305
was published
Jul 14, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
Moderate
CVE-2026-53715
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
ViewComponent: Reused Component Instances Retain Stale Render Context
Moderate
CVE-2026-54497
was published
for
view_component
(RubyGems)
Jul 15, 2026
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
High
CVE-2026-45675
was published
for
open-webui
(pip)
May 14, 2026
In the Linux kernel, the following vulnerability has been resolved:
um: Fix potential race...
High
Unreviewed
CVE-2026-53020
was published
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
ice: fix race condition in...
Moderate
Unreviewed
CVE-2026-53008
was published
Jun 24, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2026-58531
was published
Jul 14, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2026-58628
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API