GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
157 advisories
Filter by severity
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier,...
Moderate
Unreviewed
CVE-2019-8338
was published
May 24, 2022
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu...
Moderate
Unreviewed
CVE-2012-2092
was published
Apr 23, 2022
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the...
Moderate
Unreviewed
CVE-2011-3374
was published
Apr 22, 2022
Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag...
Moderate
Unreviewed
CVE-2005-2181
was published
May 1, 2022
ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not...
Moderate
Unreviewed
CVE-2002-1796
was published
Apr 30, 2022
Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID,...
Moderate
Unreviewed
CVE-2005-2182
was published
May 1, 2022
AEADs/aes-gcm: Plaintext exposed in decrypt_in_place_detached even on tag verification failure
Moderate
CVE-2023-42811
was published
for
aes-gcm
(Rust)
Sep 22, 2023
Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal...
Moderate
Unreviewed
CVE-2002-1706
was published
Apr 30, 2022
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x...
Moderate
Unreviewed
CVE-2022-42010
was published
Oct 10, 2022
A vulnerability exists in the Relion update package signature validation. A tampered update...
Moderate
Unreviewed
CVE-2022-3864
was published
Jan 4, 2024
A spoofing vulnerability exists when Windows incorrectly validates file signatures, aka 'Windows...
Moderate
Unreviewed
CVE-2020-16922
was published
May 24, 2022
Some Honor products are affected by signature management vulnerability, successful exploitation...
Moderate
Unreviewed
CVE-2023-23433
was published
Dec 29, 2023
Some Honor products are affected by signature management vulnerability, successful exploitation...
Moderate
Unreviewed
CVE-2023-23435
was published
Dec 29, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
Moderate
CVE-2023-50714
was published
for
yiisoft/yii2-authclient
(Composer)
Dec 18, 2023
Missing SSH host key validation in Mac Plugin
Moderate
CVE-2020-2146
was published
for
fr.edf.jenkins.plugins:mac
(Maven)
May 24, 2022
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an...
Moderate
Unreviewed
CVE-2023-20568
was published
Nov 14, 2023
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an...
Moderate
Unreviewed
CVE-2023-20567
was published
Nov 14, 2023
Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.
Moderate
CVE-2023-47122
was published
for
github.com/sigstore/gitsign
(Go)
Nov 14, 2023
light-oauth2 missing public key verification
Moderate
CVE-2023-31580
was published
for
com.networknt:light-oauth2
(Maven)
Oct 25, 2023
NATS TLS certificate common name validation bypass
Moderate
GHSA-wvc4-j7g5-4f79
was published
for
nats
(Rust)
Mar 27, 2023
Cargo did not verify SSH host keys
Moderate
CVE-2022-46176
was published
for
cargo
(Rust)
Jan 10, 2023
Cleartext Signed Message Signature Spoofing in openpgp
Moderate
CVE-2023-41037
was published
for
openpgp
(npm)
Aug 29, 2023
@node-saml/node-saml's validatePostRequestAsync does not include checkTimestampsValidityError
Moderate
CVE-2023-40178
was published
for
@node-saml/node-saml
(npm)
Aug 21, 2023
Golang/x/crypto message forgery vulnerability
Moderate
CVE-2019-11841
was published
for
golang.org/x/crypto
(Go)
May 24, 2022
python-apt Does Not Check Hash Signature
Moderate
CVE-2019-15796
was published
for
python-apt
(pip)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API