GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
48 advisories
Filter by severity
Pterodactyl has a database resource limit bypass via race condition in Client API
Low
CVE-2026-35202
was published
for
pterodactyl/panel
(Composer)
May 26, 2026
A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through...
Low
Unreviewed
CVE-2026-7837
was published
May 21, 2026
A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent...
Low
Unreviewed
CVE-2025-52532
was published
May 15, 2026
A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load...
Low
Unreviewed
CVE-2022-23826
was published
May 15, 2026
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
Low
CVE-2026-35353
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
Low
CVE-2026-35362
was published
for
coreutils
(Rust)
Apr 22, 2026
When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function...
Low
Unreviewed
CVE-2026-5958
was published
Apr 20, 2026
OpenClaw: TOCTOU read in exec script preflight
Low
CVE-2026-43529
was published
for
openclaw
(npm)
Apr 16, 2026
Parse Server has an MFA single-use token bypass via concurrent authData login requests
Low
CVE-2026-34224
was published
for
parse-server
(npm)
Mar 29, 2026
Handlebars.js has a Property Access Validation Bypass in container.lookup
Low
GHSA-442j-39wm-28r2
was published
for
handlebars
(npm)
Mar 29, 2026
OpenClaw may have stale policy enforcement for queued node actions
Low
CVE-2026-35648
was published
for
openclaw
(npm)
Mar 26, 2026
Parse Server: MFA recovery code single-use bypass via concurrent requests
Low
CVE-2026-33624
was published
for
parse-server
(npm)
Mar 24, 2026
Parse Server has a password reset token single-use bypass via concurrent requests
Low
CVE-2026-32943
was published
for
parse-server
(npm)
Mar 17, 2026
OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model
Low
GHSA-7qf6-h84j-8fq4
was published
for
openclaw
(npm)
Mar 3, 2026
A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data...
Low
Unreviewed
CVE-2026-21725
was published
Feb 25, 2026
Mattermost doesn't properly validate channel membership at the time of data retrieval
Low
CVE-2026-20796
was published
for
github.com/mattermost/mattermost-server
(Go)
Feb 13, 2026
Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10,...
Low
Unreviewed
CVE-2026-22281
was published
Jan 22, 2026
Keycloak does not validate and update refresh token usage atomically
Low
CVE-2026-1035
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
Turbo Frame responses can restore stale session cookies
Low
CVE-2025-66803
was published
for
@hotwired/turbo
(npm)
Jan 20, 2026
A race condition in the Nix, Lix, and Guix package managers allows the removal of content from...
Low
Unreviewed
CVE-2025-46415
was published
Jun 27, 2025
PEAK-System Driver PCANFD_ADD_FILTERS Time-Of-Check Time-Of-Use Information Disclosure...
Low
Unreviewed
CVE-2025-6217
was published
Jun 23, 2025
NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46328
was published
for
snowflake-sdk
(npm)
Apr 28, 2025
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46327
was published
for
github.com/snowflakedb/gosnowflake
(Go)
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46326
was published
for
Snowflake.Data
(NuGet)
Apr 28, 2025
IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due...
Low
Unreviewed
CVE-2025-0759
was published
Feb 27, 2025
ProTip!
Advisories are also available from the
GraphQL API