GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
689 advisories
Filter by severity
An unauthenticated attacker can crash the worklist server with a single crafted query when the...
High
Unreviewed
CVE-2026-44628
was published
Jun 30, 2026
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2,...
High
Unreviewed
CVE-2026-43705
was published
Jun 29, 2026
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
High
GHSA-f4xh-w4cj-qxq8
was published
for
langsmith
(pip)
Jun 19, 2026
CedarJava has type confusion vulnerability
High
CVE-2026-55772
was published
for
com.cedarpolicy:cedar-java
(Maven)
Jun 19, 2026
In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited...
High
Unreviewed
CVE-2026-12390
was published
Jun 18, 2026
In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type...
High
Unreviewed
CVE-2026-0162
was published
Jun 16, 2026
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox...
Moderate
Unreviewed
CVE-2026-12298
was published
Jun 16, 2026
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152...
Moderate
Unreviewed
CVE-2026-12299
was published
Jun 16, 2026
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute...
High
Unreviewed
CVE-2026-45635
was published
Jun 9, 2026
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2026-45641
was published
Jun 9, 2026
Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers...
High
Unreviewed
CVE-2026-45600
was published
Jun 9, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an...
High
Unreviewed
CVE-2026-45456
was published
Jun 9, 2026
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker...
High
Unreviewed
CVE-2026-44817
was published
Jun 9, 2026
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation...
Moderate
Unreviewed
CVE-2026-11785
was published
Jun 9, 2026
The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via...
Moderate
Unreviewed
CVE-2026-8499
was published
Jun 9, 2026
Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to...
High
Unreviewed
CVE-2026-11662
was published
Jun 9, 2026
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
Low
Unreviewed
CVE-2026-11463
was published
Jun 8, 2026
Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-11196
was published
Jun 5, 2026
Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to...
High
Unreviewed
CVE-2026-11076
was published
Jun 5, 2026
Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote...
Critical
Unreviewed
CVE-2026-11052
was published
Jun 5, 2026
Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to...
High
Unreviewed
CVE-2026-10962
was published
Jun 5, 2026
Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote...
High
Unreviewed
CVE-2026-10955
was published
Jun 5, 2026
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-10936
was published
Jun 5, 2026
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-10935
was published
Jun 5, 2026
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-10910
was published
Jun 5, 2026
ProTip!
Advisories are also available from the
GraphQL API