GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
767 advisories
Filter by severity
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote...
High
Unreviewed
CVE-2026-19316
was published
Aug 28, 2026
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with...
High
Unreviewed
CVE-2026-75159
was published
Aug 27, 2026
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel...
High
Unreviewed
CVE-2026-18798
was published
Aug 25, 2026
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that...
High
Unreviewed
CVE-2026-47895
was published
Aug 23, 2026
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU...
Moderate
Unreviewed
CVE-2026-45202
was published
Aug 21, 2026
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed...
Moderate
Unreviewed
CVE-2026-18663
was published
Aug 12, 2026
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-65780
was published
Aug 11, 2026
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-62889
was published
Aug 11, 2026
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2026-62766
was published
Aug 11, 2026
Double free in Windows Network Connection Broker allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-61366
was published
Aug 11, 2026
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote...
High
Unreviewed
CVE-2026-20338
was published
Aug 7, 2026
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI...
High
Unreviewed
CVE-2026-43622
was published
Aug 6, 2026
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.
...
High
Unreviewed
CVE-2026-55995
was published
Jul 29, 2026
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file...
Moderate
Unreviewed
CVE-2026-17573
was published
Jul 27, 2026
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
High
Unreviewed
CVE-2026-66373
was published
Jul 25, 2026
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the...
High
Unreviewed
CVE-2026-66032
was published
Jul 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: net2280: Fix...
High
Unreviewed
CVE-2026-64242
was published
Jul 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: fix double...
High
Unreviewed
CVE-2026-64224
was published
Jul 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-pf: avoid double...
High
Unreviewed
CVE-2026-64222
was published
Jul 24, 2026
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC...
High
Unreviewed
CVE-2026-64832
was published
Jul 22, 2026
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in...
Critical
Unreviewed
CVE-2026-64621
was published
Jul 20, 2026
In the Linux kernel, the following vulnerability has been resolved:
qed: fix double free in...
High
Unreviewed
CVE-2026-64118
was published
Jul 19, 2026
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor...
Moderate
Unreviewed
CVE-2026-13713
was published
Jul 17, 2026
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2026-55132
was published
Jul 14, 2026
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
High
Unreviewed
CVE-2026-50685
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API