GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
689 advisories
Filter by severity
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An...
High
Unreviewed
CVE-2026-14644
was published
Aug 7, 2026
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
Moderate
CVE-2026-54164
was published
for
api-platform/core
(Composer)
Aug 7, 2026
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache...
Critical
Unreviewed
CVE-2026-71558
was published
Aug 7, 2026
A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The ...
High
Unreviewed
CVE-2026-15572
was published
Aug 5, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based)...
High
Unreviewed
CVE-2026-66321
was published
Aug 4, 2026
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-17989
was published
Jul 30, 2026
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a...
High
Unreviewed
CVE-2026-17948
was published
Jul 30, 2026
Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote...
Moderate
Unreviewed
CVE-2026-17866
was published
Jul 30, 2026
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-17725
was published
Jul 30, 2026
Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had...
Critical
Unreviewed
CVE-2026-17687
was published
Jul 30, 2026
Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to...
Critical
Unreviewed
CVE-2026-17697
was published
Jul 30, 2026
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
High
CVE-2026-55771
was published
for
com.cedarpolicy:cedar-java
(Maven)
Jul 28, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2026-64727
was published
Jul 27, 2026
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.6 and...
Moderate
Unreviewed
CVE-2026-64693
was published
Jul 27, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2026-64704
was published
Jul 27, 2026
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
Critical
CVE-2026-59940
was published
for
seroval
(npm)
Jul 24, 2026
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
High
GHSA-2x35-3fw4-9jr4
was published
for
n8n
(npm)
Jul 22, 2026
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side...
High
Unreviewed
CVE-2026-13066
was published
Jul 22, 2026
Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to...
High
Unreviewed
CVE-2026-16420
was published
Jul 22, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-16410
was published
Jul 21, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-16355
was published
Jul 21, 2026
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
High
CVE-2026-57108
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jul 20, 2026
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote...
High
Unreviewed
CVE-2026-15776
was published
Jul 14, 2026
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized...
High
Unreviewed
CVE-2026-58541
was published
Jul 14, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an...
High
Unreviewed
CVE-2026-55022
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API