GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
689 advisories
Filter by severity
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation...
Moderate
Unreviewed
CVE-2026-11785
was published
Jun 9, 2026
libxslt Type Confusion vulnerability that affects Nokogiri
High
CVE-2019-13118
was published
for
nokogiri
(RubyGems)
May 24, 2022
The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via...
Moderate
Unreviewed
CVE-2026-8499
was published
Jun 9, 2026
Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to...
High
Unreviewed
CVE-2026-11662
was published
Jun 9, 2026
free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible types
High
CVE-2026-44325
was published
for
github.com/free5gc/nrf
(Go)
May 8, 2026
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
High
CVE-2026-44728
was published
for
@babel/plugin-transform-modules-systemjs
(npm)
May 8, 2026
Access of Resource Using Incompatible Type ('Type Confusion') in yourls/yourls
Critical
CVE-2019-14537
was published
for
yourls/yourls
(Composer)
Sep 23, 2019
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
Low
Unreviewed
CVE-2026-11463
was published
Jun 8, 2026
Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote...
High
Unreviewed
CVE-2026-10955
was published
Jun 5, 2026
Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote...
Critical
Unreviewed
CVE-2026-11052
was published
Jun 5, 2026
Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-11196
was published
Jun 5, 2026
Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to...
High
Unreviewed
CVE-2026-11076
was published
Jun 5, 2026
Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to...
High
Unreviewed
CVE-2026-10962
was published
Jun 5, 2026
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-10910
was published
Jun 5, 2026
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-10936
was published
Jun 5, 2026
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-10935
was published
Jun 5, 2026
In AzeoTech DAQFactory release 20.7 (Build 2555), an Access of Resource Using Incompatible Type...
High
Unreviewed
CVE-2025-66586
was published
Dec 11, 2025
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet...
Moderate
Unreviewed
CVE-2026-48682
was published
Jun 2, 2026
Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys...
High
Unreviewed
CVE-2026-9334
was published
Jun 3, 2026
tar has a PAX header desynchronization issue
Moderate
GHSA-3pv8-6f4r-ffg2
was published
for
tar
(Rust)
May 29, 2026
astral-tokio-tar has a PAX Header Desynchronization issue
Moderate
GHSA-3cv2-h65g-fgmm
was published
for
astral-tokio-tar
(Rust)
May 29, 2026
Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to...
High
Unreviewed
CVE-2026-9983
was published
May 29, 2026
Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a...
High
Unreviewed
CVE-2026-10022
was published
May 29, 2026
Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a...
High
Unreviewed
CVE-2026-9117
was published
May 20, 2026
tar-rs incorrectly ignores PAX size headers if header size is nonzero
Moderate
CVE-2026-33055
was published
for
tar
(Rust)
Mar 20, 2026
ProTip!
Advisories are also available from the
GraphQL API