GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile
Critical
CVE-2026-41296
was published
for
openclaw
(npm)
Apr 3, 2026
A race condition was addressed with improved handling of symbolic links. This issue is fixed in...
Critical
Unreviewed
CVE-2026-20677
was published
Feb 12, 2026
@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses
Critical
CVE-2026-25641
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
Critical
CVE-2026-25052
was published
for
n8n
(npm)
Feb 4, 2026
It was found that the XPC service offered by the privileged helper of Native Access uses the PID...
Critical
Unreviewed
CVE-2026-24071
was published
Feb 2, 2026
Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local...
Critical
Unreviewed
CVE-2025-13032
was published
Nov 11, 2025
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the...
Critical
Unreviewed
CVE-2025-34027
was published
May 22, 2025
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that...
Critical
Unreviewed
CVE-2025-22224
was published
Mar 4, 2025
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker...
Critical
Unreviewed
CVE-2024-41787
was published
Jan 10, 2025
IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote...
Critical
Unreviewed
CVE-2024-41779
was published
Nov 22, 2024
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
Critical
CVE-2024-0132
was published
for
github.com/NVIDIA/nvidia-container-toolkit
(Go)
Oct 29, 2024
Waitress has request processing race condition in HTTP pipelining with invalid first request
Critical
CVE-2024-49768
was published
for
waitress
(pip)
Oct 29, 2024
Duplicate Advisory: NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
Critical
GHSA-536j-xxhg-6pgg
was published
for
github.com/NVIDIA/nvidia-container-toolkit
(Go)
Sep 26, 2024
•
withdrawn
Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability...
Critical
Unreviewed
CVE-2023-32156
was published
May 3, 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16...
Critical
Unreviewed
CVE-2023-4008
was published
Aug 3, 2023
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check...
Critical
Unreviewed
CVE-2019-7249
was published
May 13, 2022
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
Critical
CVE-2021-32708
was published
for
league/flysystem
(Composer)
Jun 29, 2021
ProTip!
Advisories are also available from the
GraphQL API