GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
689 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
ip6_tunnel: clear skb2->cb[]...
Critical
Unreviewed
CVE-2026-43037
was published
May 1, 2026
Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to...
High
Unreviewed
CVE-2026-7337
was published
Apr 29, 2026
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially...
Moderate
Unreviewed
CVE-2026-6732
was published
Apr 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
team: fix header_ops type...
High
Unreviewed
CVE-2026-31502
was published
Apr 22, 2026
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to...
High
Unreviewed
CVE-2026-6301
was published
Apr 15, 2026
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to...
High
Unreviewed
CVE-2026-6307
was published
Apr 15, 2026
Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to...
High
Unreviewed
CVE-2026-6363
was published
Apr 15, 2026
Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using...
High
Unreviewed
CVE-2026-27298
was published
Apr 15, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
High
CVE-2026-40683
was published
for
keystone
(pip)
Apr 14, 2026
Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized...
High
Unreviewed
CVE-2026-26162
was published
Apr 14, 2026
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized...
Moderate
Unreviewed
CVE-2026-20806
was published
Apr 14, 2026
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in...
Critical
Unreviewed
CVE-2025-70023
was published
Apr 14, 2026
Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open...
Moderate
Unreviewed
CVE-2026-40446
was published
Apr 13, 2026
Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution...
High
Unreviewed
CVE-2026-5496
was published
Apr 11, 2026
Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a...
High
Unreviewed
CVE-2026-5914
was published
Apr 9, 2026
Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-5871
was published
Apr 9, 2026
Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-5865
was published
Apr 9, 2026
The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op...
High
Unreviewed
CVE-2026-27144
was published
Apr 8, 2026
DynFuture Drop Can Construct a Dangling Reference
Moderate
GHSA-j3w3-p6mr-3hrh
was published
for
dyn-future
(Rust)
Apr 4, 2026
Roundcube Webmail: Incorrect password comparison in the password plugin
Moderate
CVE-2026-35541
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS...
Low
Unreviewed
CVE-2025-43236
was published
Apr 2, 2026
A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of...
Moderate
Unreviewed
CVE-2026-5360
was published
Apr 2, 2026
Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value
Moderate
CVE-2026-34595
was published
for
parse-server
(npm)
Apr 1, 2026
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received...
High
Unreviewed
CVE-2026-21710
was published
Mar 30, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
High
CVE-2026-33940
was published
for
handlebars
(npm)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API