GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
773 advisories
Filter by severity
Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization...
Unknown
Unreviewed
CVE-2026-73179
was published
Oct 9, 2026
PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
High
CVE-2026-60091
was published
for
praisonai
(pip)
Oct 8, 2026
An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to...
High
Unreviewed
CVE-2026-67693
was published
Oct 8, 2026
PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure
High
CVE-2026-61430
was published
for
praisonaiagents
(pip)
Oct 8, 2026
Docling has SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resolution; no IP validation in HTML render mode)
Moderate
CVE-2026-105743
was published
for
docling
(pip)
Oct 7, 2026
yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user
High
CVE-2026-106451
was published
for
at.yawk.lz4:lz4-java
(Maven)
Oct 7, 2026
Ghost: Server-Side Request Forgery in Bookmark Fetching
Moderate
CVE-2026-105647
was published
for
ghost
(npm)
Oct 7, 2026
PraisonAI: Crawl4AI/Chromium backend is also affected by the `web_crawl` SSRF validation bypass
High
CVE-2026-61429
was published
for
praisonaiagents
(pip)
Oct 7, 2026
Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who...
Moderate
Unreviewed
CVE-2026-106413
was published
Oct 6, 2026
Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote...
High
Unreviewed
CVE-2026-106412
was published
Oct 6, 2026
Race condition in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a...
Moderate
Unreviewed
CVE-2026-106405
was published
Oct 6, 2026
Race condition in CacheStorage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-106300
was published
Oct 6, 2026
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute...
High
Unreviewed
CVE-2026-106207
was published
Oct 6, 2026
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of...
Moderate
Unreviewed
CVE-2026-77804
was published
Oct 5, 2026
LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in...
Moderate
Unreviewed
CVE-2026-105130
was published
Oct 4, 2026
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup...
Moderate
Unreviewed
CVE-2026-104474
was published
Oct 3, 2026
NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing...
High
Unreviewed
CVE-2026-47497
was published
Sep 30, 2026
Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-95360
was published
Sep 29, 2026
Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker...
High
Unreviewed
CVE-2026-95344
was published
Sep 29, 2026
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition...
High
Unreviewed
CVE-2026-92369
was published
Sep 29, 2026
Electron: Local race condition in Squirrel.Mac update installation on macOS
Moderate
CVE-2026-102672
was published
for
electron
(npm)
Sep 29, 2026
Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service...
Moderate
Unreviewed
CVE-2026-101088
was published
Sep 27, 2026
Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH...
High
Unreviewed
CVE-2026-100713
was published
Sep 26, 2026
OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use...
High
Unreviewed
CVE-2026-100597
was published
Sep 26, 2026
9router: Image prefetch DNS rebinding allows SSRF to internal services
High
CVE-2026-56676
was published
for
9router
(npm)
Sep 23, 2026
ProTip!
Advisories are also available from the
GraphQL API