GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
429 advisories
Filter by severity
whatsapp-api-js fails to validate message's signature
Moderate
CVE-2024-45607
was published
for
whatsapp-api-js
(npm)
Sep 12, 2024
Improper Verification of Cryptographic Signature in aws-encryption-sdk-java
Moderate
CVE-2024-23680
was published
for
com.amazonaws:aws-encryption-sdk-java
(Maven)
Jan 19, 2024
There is a possible escalation of privilege due to improperly used crypto. This could lead to...
Critical
Unreviewed
CVE-2024-32911
was published
Jun 13, 2024
An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware...
High
Unreviewed
CVE-2023-52043
was published
Apr 4, 2024
Gentoo Portage missing PGP validation of executed code
High
CVE-2016-20021
was published
for
portage
(pip)
Jan 12, 2024
Adyen APIs Library for Python timing attack vulnerability
Moderate
GHSA-f3q4-ggfp-jv34
was published
for
Adyen
(pip)
Aug 30, 2024
Hyperledger Indy's update process of a DID does not check who signs the request
High
CVE-2020-11093
was published
for
indy-node
(pip)
Aug 30, 2024
In Bouncy Castle JCE Provider it is possible to inject extra elements in the sequence making up the signature and still have it validate
High
CVE-2016-1000338
was published
for
org.bouncycastle:bcprov-jdk14
(Maven)
Oct 17, 2018
Authlib has algorithm confusion with asymmetric public keys
High
CVE-2024-37568
was published
for
authlib
(pip)
Jun 9, 2024
Elliptic's EDDSA missing signature length check
Low
CVE-2024-42459
was published
for
elliptic
(npm)
Aug 2, 2024
Elliptic allows BER-encoded signatures
Low
CVE-2024-42461
was published
for
elliptic
(npm)
Aug 2, 2024
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables...
Moderate
Unreviewed
CVE-2024-41258
was published
Jul 31, 2024
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to...
Moderate
Unreviewed
CVE-2024-5912
was published
Jul 10, 2024
An Improper Validation of signature in Zscaler Client Connector on Windows allows an...
Moderate
Unreviewed
CVE-2023-28806
was published
Aug 6, 2024
Anti-tampering can be disabled under certain conditions without signature validation. This...
High
Unreviewed
CVE-2024-23456
was published
Aug 6, 2024
The Zscaler Updater process does not validate the digital signature of the installer before...
Moderate
Unreviewed
CVE-2024-23460
was published
Aug 6, 2024
A spoofing vulnerability exists when Windows incorrectly validates file signatures, aka 'Windows...
Low
Unreviewed
CVE-2020-1464
was published
May 24, 2022
Windows Enroll Engine Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-38069
was published
Jul 9, 2024
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x...
High
Unreviewed
CVE-2023-34435
was published
Jul 8, 2024
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate...
Moderate
Unreviewed
CVE-2024-0567
was published
Jan 16, 2024
xml-crypto vulnerable to XML signature verification bypass due improper verification of signature/signature spoofing
Critical
CVE-2024-32962
was published
for
xml-crypto
(npm)
May 1, 2024
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local...
Moderate
Unreviewed
CVE-2024-20892
was published
Jul 2, 2024
Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client"...
Critical
Unreviewed
CVE-2024-36277
was published
Jun 17, 2024
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Moderate
CVE-2022-23540
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an...
High
Unreviewed
CVE-2024-37532
was published
Jun 20, 2024
ProTip!
Advisories are also available from the
GraphQL API