GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,586
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
757 advisories
Filter by severity
NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing...
High
Unreviewed
CVE-2026-47497
was published
Sep 30, 2026
Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-95360
was published
Sep 29, 2026
Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker...
High
Unreviewed
CVE-2026-95344
was published
Sep 29, 2026
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition...
High
Unreviewed
CVE-2026-92369
was published
Sep 29, 2026
Electron: Local race condition in Squirrel.Mac update installation on macOS
Moderate
CVE-2026-102672
was published
for
electron
(npm)
Sep 29, 2026
Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service...
Moderate
Unreviewed
CVE-2026-101088
was published
Sep 27, 2026
Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH...
High
Unreviewed
CVE-2026-100713
was published
Sep 26, 2026
OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use...
High
Unreviewed
CVE-2026-100597
was published
Sep 26, 2026
9router: Image prefetch DNS rebinding allows SSRF to internal services
High
CVE-2026-56676
was published
for
9router
(npm)
Sep 23, 2026
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be...
High
Unreviewed
CVE-2026-91813
was published
Sep 23, 2026
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
High
CVE-2026-77633
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C...
Moderate
Unreviewed
CVE-2026-86805
was published
Sep 22, 2026
Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker...
Low
Unreviewed
CVE-2026-93380
was published
Sep 17, 2026
Memory Corruption when processing I2C transfer requests due to a race condition between memory...
High
Unreviewed
CVE-2026-25278
was published
Sep 17, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19...
Moderate
Unreviewed
CVE-2024-11222
was published
Sep 16, 2026
Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a...
Moderate
Unreviewed
CVE-2026-91744
was published
Sep 15, 2026
Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote...
High
Unreviewed
CVE-2026-91748
was published
Sep 15, 2026
Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had...
High
Unreviewed
CVE-2026-91743
was published
Sep 15, 2026
Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote...
High
Unreviewed
CVE-2026-91712
was published
Sep 15, 2026
The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is...
High
Unreviewed
CVE-2026-79994
was published
Sep 15, 2026
Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who...
Low
Unreviewed
CVE-2026-91708
was published
Sep 15, 2026
CrowdStrike released a security update to address a vulnerability in the Falcon sensor for...
High
Unreviewed
CVE-2026-40058
was published
Sep 15, 2026
Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls...
Critical
Unreviewed
CVE-2026-77972
was published
Sep 15, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file...
Moderate
Unreviewed
CVE-2026-18069
was published
Sep 14, 2026
Description
The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker...
Unknown
Unreviewed
CVE-2026-82429
was published
Sep 14, 2026
ProTip!
Advisories are also available from the
GraphQL API