GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
2,559 advisories
Filter by severity
IBM Guardium Data Protection 12.2.2 could allow a remote attacker to cause a denial of service...
High
Unreviewed
CVE-2026-84230
was published
Oct 9, 2026
IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch...
High
Unreviewed
CVE-2026-84271
was published
Oct 8, 2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')...
Moderate
Unreviewed
CVE-2026-42698
was published
Oct 8, 2026
A race condition and thread-safety vulnerability exists in the web management daemon of Brocade...
Low
Unreviewed
CVE-2026-94584
was published
Oct 8, 2026
A race condition vulnerability exists in the request processing logic of the REST management...
Low
Unreviewed
CVE-2026-94583
was published
Oct 8, 2026
MISP contains a race condition in the email-based one-time password (OTP) login flow. When two...
Moderate
Unreviewed
CVE-2026-107276
was published
Oct 7, 2026
Backstage: Improper task state validation in Scaffolder backend
High
CVE-2026-106500
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Oct 7, 2026
In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could...
High
Unreviewed
CVE-2026-56906
was published
Oct 6, 2026
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to...
High
Unreviewed
CVE-2026-106426
was published
Oct 6, 2026
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had...
High
Unreviewed
CVE-2026-106377
was published
Oct 6, 2026
Race condition in Chromoting in Google Chrome prior to 155.0.8059.39 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-106385
was published
Oct 6, 2026
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to...
High
Unreviewed
CVE-2026-106255
was published
Oct 6, 2026
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had...
High
Unreviewed
CVE-2026-106238
was published
Oct 6, 2026
Race condition in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-106213
was published
Oct 6, 2026
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-106201
was published
Oct 6, 2026
Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability...
High
Unreviewed
CVE-2026-105773
was published
Oct 5, 2026
In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due...
High
Unreviewed
CVE-2026-58880
was published
Oct 5, 2026
Concurrent execution using shared resource with improper synchronization ('race condition')...
High
Unreviewed
CVE-2026-104714
was published
Oct 5, 2026
A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This...
Moderate
Unreviewed
CVE-2026-105163
was published
Oct 5, 2026
Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup...
Moderate
Unreviewed
CVE-2026-105112
was published
Oct 3, 2026
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
Low
CVE-2026-104855
was published
for
wasmtime
(Rust)
Oct 2, 2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')...
Low
Unreviewed
CVE-2026-39601
was published
Oct 2, 2026
Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized...
High
Unreviewed
CVE-2026-104057
was published
Oct 1, 2026
Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance...
Moderate
Unreviewed
CVE-2026-103282
was published
Oct 1, 2026
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a...
Moderate
Unreviewed
CVE-2026-47565
was published
Sep 30, 2026
ProTip!
Advisories are also available from the
GraphQL API