GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
292 advisories
Filter by severity
Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag...
Moderate
Unreviewed
CVE-2005-2181
was published
May 1, 2022
ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not...
Moderate
Unreviewed
CVE-2002-1796
was published
Apr 30, 2022
Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal...
Moderate
Unreviewed
CVE-2002-1706
was published
Apr 30, 2022
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu...
Moderate
Unreviewed
CVE-2012-2092
was published
Apr 23, 2022
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the...
Moderate
Unreviewed
CVE-2011-3374
was published
Apr 22, 2022
An improper verification of the cryptographic signature of firmware updates of the B. Braun...
High
Unreviewed
CVE-2020-25166
was published
Apr 15, 2022
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21,...
High
Unreviewed
CVE-2021-30066
was published
Apr 5, 2022
AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies,...
High
Unreviewed
CVE-2021-32977
was published
Apr 5, 2022
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first...
High
Unreviewed
CVE-2015-3298
was published
Mar 31, 2022
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse...
Moderate
Unreviewed
CVE-2021-43393
was published
Mar 5, 2022
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain...
Moderate
Unreviewed
CVE-2021-43392
was published
Mar 5, 2022
Local privilege escalation due to unrestricted loading of unsigned libraries. The following...
High
Unreviewed
CVE-2022-24115
was published
Feb 11, 2022
There is a vulnerability of signature verification mechanism failure in system upgrade through...
Moderate
Unreviewed
CVE-2021-40045
was published
Feb 11, 2022
The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.
High
Unreviewed
CVE-2020-16154
was published
Feb 10, 2022
A firmware update vulnerability exists in the "update" firmware checks functionality of...
High
Unreviewed
CVE-2022-21134
was published
Jan 29, 2022
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that...
Moderate
Unreviewed
CVE-2021-20156
was published
Dec 31, 2021
CPAN 2.28 allows Signature Verification Bypass.
High
Unreviewed
CVE-2020-16156
was published
Dec 14, 2021
ProTip!
Advisories are also available from the
GraphQL API