GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
69 advisories
Filter by severity
Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache...
Critical
Unreviewed
CVE-2026-71558
was published
Aug 7, 2026
Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to...
Critical
Unreviewed
CVE-2026-17697
was published
Jul 30, 2026
Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had...
Critical
Unreviewed
CVE-2026-17687
was published
Jul 30, 2026
In the Linux kernel, the following vulnerability has been resolved:
ip6_tunnel: clear skb2->cb[]...
Critical
Unreviewed
CVE-2026-43037
was published
May 1, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2026-64727
was published
Jul 27, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2026-64704
was published
Jul 27, 2026
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
Critical
CVE-2026-59940
was published
for
seroval
(npm)
Jul 24, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-16410
was published
Jul 21, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-16355
was published
Jul 21, 2026
In the Linux kernel, the following vulnerability has been resolved:
ipv6: icmp: clear skb2->cb[]...
Critical
Unreviewed
CVE-2026-43038
was published
May 1, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based)...
Critical
Unreviewed
CVE-2026-58289
was published
Jul 3, 2026
Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to...
Critical
Unreviewed
CVE-2026-14423
was published
Jul 2, 2026
Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to...
Critical
Unreviewed
CVE-2026-13883
was published
Jul 1, 2026
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had...
Critical
Unreviewed
CVE-2026-13776
was published
Jul 1, 2026
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability affects Firefox <...
Critical
Unreviewed
CVE-2026-2796
was published
Feb 24, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox <...
Critical
Unreviewed
CVE-2026-4698
was published
Mar 24, 2026
Access of Resource Using Incompatible Type ('Type Confusion') in yourls/yourls
Critical
CVE-2019-14537
was published
for
yourls/yourls
(Composer)
Sep 23, 2019
Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote...
Critical
Unreviewed
CVE-2026-11052
was published
Jun 5, 2026
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in...
Critical
Unreviewed
CVE-2025-70023
was published
Apr 14, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion
Critical
CVE-2026-33937
was published
for
handlebars
(npm)
Mar 27, 2026
JIT miscompilation in the JavaScript Engine component. This vulnerability affects Firefox < 149...
Critical
Unreviewed
CVE-2026-4702
was published
Mar 24, 2026
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized...
Critical
Unreviewed
CVE-2026-24874
was published
Jan 27, 2026
A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT...
Critical
Unreviewed
CVE-2025-65570
was published
Dec 29, 2025
Permission control vulnerability in the memory management module.
Impact: Successful exploitation...
Critical
Unreviewed
CVE-2025-64314
was published
Nov 28, 2025
The type inference system allows the compilation of functions that can cause type confusions...
Critical
Unreviewed
CVE-2019-9791
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API