GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,152 advisories
Filter by severity
A denial-of-service
vulnerability exists in httpd service on Archer A6 v4 where the asynchronous...
Moderate
Unreviewed
CVE-2026-9030
was published
Aug 7, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition...
Moderate
Unreviewed
CVE-2026-47620
was published
Aug 4, 2026
A race
condition exists in the cloud-based Omada device adoption process when an
attacker may be...
Moderate
Unreviewed
CVE-2025-15630
was published
Aug 3, 2026
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by...
Moderate
Unreviewed
CVE-2026-44102
was published
Jul 30, 2026
Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17999
was published
Jul 30, 2026
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-17822
was published
Jul 30, 2026
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-17841
was published
Jul 30, 2026
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-17724
was published
Jul 30, 2026
Accessing the vNUMA configuration data of a guest is still possible when
domain destruction has...
Moderate
Unreviewed
CVE-2026-62429
was published
Jul 28, 2026
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
Moderate
Unreviewed
CVE-2026-62435
was published
Jul 28, 2026
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
Moderate
Unreviewed
CVE-2026-62436
was published
Jul 28, 2026
A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS...
Moderate
Unreviewed
CVE-2026-43811
was published
Jul 27, 2026
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2026-43770
was published
Jul 27, 2026
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2026-43781
was published
Jul 27, 2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
Moderate
Unreviewed
CVE-2026-60161
was published
Jul 22, 2026
hono/jsx does not isolate context per request, leading to cross-request data disclosure
Moderate
CVE-2026-59896
was published
for
hono
(npm)
Jul 21, 2026
IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an...
Moderate
Unreviewed
CVE-2026-15995
was published
Jul 17, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
Moderate
CVE-2026-53715
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
ViewComponent: Reused Component Instances Retain Stale Render Context
Moderate
CVE-2026-54497
was published
for
view_component
(RubyGems)
Jul 15, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
Moderate
Unreviewed
CVE-2026-58543
was published
Jul 14, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
Moderate
Unreviewed
CVE-2026-56649
was published
Jul 14, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in...
Moderate
Unreviewed
CVE-2026-55945
was published
Jul 3, 2026
goshs: Share-link ?token=… redemption races past download limit
Moderate
CVE-2026-50139
was published
for
goshs.de/goshs/v2
(Go)
Jul 1, 2026
In the Linux kernel, the following vulnerability has been resolved:
signal: clear...
Moderate
Unreviewed
CVE-2026-53352
was published
Jul 1, 2026
Race in History Embeddings in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-14133
was published
Jul 1, 2026
ProTip!
Advisories are also available from the
GraphQL API