GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
689 advisories
Filter by severity
Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote...
Low
Unreviewed
CVE-2026-8554
was published
May 14, 2026
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-8570
was published
May 14, 2026
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to...
High
Unreviewed
CVE-2026-8540
was published
May 14, 2026
TanStack Start - Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function
Moderate
GHSA-9m65-766c-r333
was published
for
@tanstack/start-server-core
(npm)
May 14, 2026
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function...
High
Unreviewed
CVE-2026-34344
was published
May 12, 2026
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an...
High
Unreviewed
CVE-2026-35417
was published
May 12, 2026
Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server...
High
Unreviewed
CVE-2024-6119
was published
Sep 3, 2024
Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to...
High
Unreviewed
CVE-2026-7988
was published
May 6, 2026
Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to...
High
Unreviewed
CVE-2026-7927
was published
May 6, 2026
Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a...
High
Unreviewed
CVE-2026-7914
was published
May 6, 2026
astral-tokio-tar is Vulnerable to PAX Header Desynchronization
Moderate
GHSA-fp55-jw48-c537
was published
for
astral-tokio-tar
(Rust)
May 6, 2026
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local...
Moderate
Unreviewed
CVE-2026-20451
was published
May 4, 2026
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
Low
Unreviewed
CVE-2026-43862
was published
May 4, 2026
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially...
Moderate
Unreviewed
CVE-2026-6732
was published
Apr 24, 2026
Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to...
High
Unreviewed
CVE-2026-7337
was published
Apr 29, 2026
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet...
High
Unreviewed
CVE-2025-7424
was published
Jul 10, 2025
A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func...
Low
Unreviewed
CVE-2025-11731
was published
Oct 14, 2025
The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op...
High
Unreviewed
CVE-2026-27144
was published
Apr 8, 2026
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in...
Critical
Unreviewed
CVE-2025-70023
was published
Apr 14, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
High
CVE-2026-40683
was published
for
keystone
(pip)
Apr 14, 2026
Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to...
High
Unreviewed
CVE-2026-6363
was published
Apr 15, 2026
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to...
High
Unreviewed
CVE-2026-6301
was published
Apr 15, 2026
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to...
High
Unreviewed
CVE-2026-6307
was published
Apr 15, 2026
Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using...
High
Unreviewed
CVE-2026-27298
was published
Apr 15, 2026
Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized...
High
Unreviewed
CVE-2026-26162
was published
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API