GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,437
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,695
Pub
13
RubyGems
1,031
Rust
1,222
Swift
53
Unreviewed advisories
All unreviewed
5,000+
573 advisories
Filter by severity
Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a...
High
Unreviewed
CVE-2026-5914
was published
Apr 9, 2026
Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute...
Unknown
Unreviewed
CVE-2026-5871
was published
Apr 9, 2026
Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute...
Unknown
Unreviewed
CVE-2026-5865
was published
Apr 9, 2026
DynFuture Drop Can Construct a Dangling Reference
Moderate
GHSA-j3w3-p6mr-3hrh
was published
for
dyn-future
(Rust)
Apr 4, 2026
Roundcube Webmail: Incorrect password comparison in the password plugin
Moderate
CVE-2026-35541
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS...
Low
Unreviewed
CVE-2025-43236
was published
Apr 2, 2026
A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of...
Moderate
Unreviewed
CVE-2026-5360
was published
Apr 2, 2026
Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value
Moderate
CVE-2026-34595
was published
for
parse-server
(npm)
Apr 1, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
High
CVE-2026-33940
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
High
CVE-2026-33938
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion
Critical
CVE-2026-33937
was published
for
handlebars
(npm)
Mar 27, 2026
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26...
Moderate
Unreviewed
CVE-2026-28822
was published
Mar 25, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox <...
Critical
Unreviewed
CVE-2026-4698
was published
Mar 24, 2026
JIT miscompilation in the JavaScript Engine component. This vulnerability affects Firefox < 149...
Critical
Unreviewed
CVE-2026-4702
was published
Mar 24, 2026
tar-rs incorrectly ignores PAX size headers if header size is nonzero
Moderate
CVE-2026-33055
was published
for
tar
(Rust)
Mar 20, 2026
Qwik City has array method pollution in FormData processing allows type confusion and DoS
High
CVE-2026-32701
was published
for
@builder.io/qwik-city
(npm)
Mar 20, 2026
Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to...
High
Unreviewed
CVE-2026-4457
was published
Mar 20, 2026
A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially...
High
Unreviewed
CVE-2025-66342
was published
Mar 17, 2026
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre...
Moderate
Unreviewed
CVE-2025-25277
was published
Mar 16, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an...
High
Unreviewed
CVE-2026-26110
was published
Mar 10, 2026
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This...
High
Unreviewed
CVE-2026-2783
was published
Feb 24, 2026
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability affects Firefox <...
Critical
Unreviewed
CVE-2026-2796
was published
Feb 24, 2026
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
Moderate
GHSA-88qp-p4qg-rqm6
was published
for
@sveltejs/kit
(npm)
Feb 19, 2026
PyO3 has type confusion when accessing data from sublasses of subclasses of native types with `abi3` feature
High
GHSA-47qc-857f-7w7f
was published
for
pyo3
(Rust)
Feb 19, 2026
The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-14799
was published
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API