GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
775 advisories
Filter by severity
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote...
High
Unreviewed
CVE-2026-19316
was published
Aug 28, 2026
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with...
High
Unreviewed
CVE-2026-75159
was published
Aug 27, 2026
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel...
High
Unreviewed
CVE-2026-18798
was published
Aug 25, 2026
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that...
High
Unreviewed
CVE-2026-47895
was published
Aug 23, 2026
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU...
Moderate
Unreviewed
CVE-2026-45202
was published
Aug 21, 2026
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed...
Moderate
Unreviewed
CVE-2026-18663
was published
Aug 12, 2026
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-65780
was published
Aug 11, 2026
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-62889
was published
Aug 11, 2026
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-62766
was published
Aug 11, 2026
Double free in Windows Network Connection Broker allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-61366
was published
Aug 11, 2026
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote...
High
Unreviewed
CVE-2026-20338
was published
Aug 7, 2026
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI...
High
Unreviewed
CVE-2026-43622
was published
Aug 6, 2026
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.
...
High
Unreviewed
CVE-2026-55995
was published
Jul 29, 2026
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file...
Moderate
Unreviewed
CVE-2026-17573
was published
Jul 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
staging: media: ipu7: fix...
High
Unreviewed
CVE-2026-64447
was published
Jul 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free...
High
Unreviewed
CVE-2026-64382
was published
Jul 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free...
Critical
Unreviewed
CVE-2026-64385
was published
Jul 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free...
Critical
Unreviewed
CVE-2026-64383
was published
Jul 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix query_info(...
Critical
Unreviewed
CVE-2026-64386
was published
Jul 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix query...
Critical
Unreviewed
CVE-2026-64387
was published
Jul 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix change...
Critical
Unreviewed
CVE-2026-64384
was published
Jul 25, 2026
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
High
Unreviewed
CVE-2026-66373
was published
Jul 25, 2026
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the...
High
Unreviewed
CVE-2026-66032
was published
Jul 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: net2280: Fix...
High
Unreviewed
CVE-2026-64242
was published
Jul 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: fix double...
High
Unreviewed
CVE-2026-64224
was published
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API