GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
111 advisories
Filter by severity
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8,...
Moderate
Unreviewed
CVE-2023-1204
was published
May 3, 2023
An improper verification of cryptographic signature vulnerability was identified in GitHub...
Moderate
Unreviewed
CVE-2025-23369
was published
Jan 21, 2025
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned...
Moderate
Unreviewed
CVE-2024-7344
was published
Jan 14, 2025
StorageGRID (formerly StorageGRID Webscale) versions prior to
11.7.0.9 and 11.8.0.5 are...
Moderate
Unreviewed
CVE-2024-21988
was published
Jun 15, 2024
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is...
Moderate
Unreviewed
CVE-2023-3347
was published
Jul 20, 2023
The application failed to account for exceptions thrown by the `loadManifestFromFile` method...
Moderate
Unreviewed
CVE-2024-11696
was published
Nov 26, 2024
The Portable Document Format (PDF) specification does not provide any information regarding the...
Moderate
Unreviewed
CVE-2018-18689
was published
May 24, 2022
A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense ...
Moderate
Unreviewed
CVE-2020-3308
was published
May 24, 2022
A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could...
Moderate
Unreviewed
CVE-2021-1461
was published
Nov 18, 2024
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing...
Moderate
Unreviewed
CVE-2024-49394
was published
Nov 12, 2024
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE...
Moderate
Unreviewed
CVE-2024-8036
was published
Oct 25, 2024
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey()...
Moderate
Unreviewed
CVE-2024-41254
was published
Jul 31, 2024
Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2024-23960
was published
Sep 28, 2024
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5...
Moderate
Unreviewed
CVE-2024-27247
was published
Apr 9, 2024
Improper privilege management in the installer for Zoom Desktop Client for Windows before version...
Moderate
Unreviewed
CVE-2024-24694
was published
Apr 9, 2024
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for...
Moderate
Unreviewed
CVE-2024-27244
was published
May 15, 2024
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated...
Moderate
Unreviewed
CVE-2023-49646
was published
Dec 14, 2023
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables...
Moderate
Unreviewed
CVE-2024-41258
was published
Jul 31, 2024
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to...
Moderate
Unreviewed
CVE-2024-5912
was published
Jul 10, 2024
An Improper Validation of signature in Zscaler Client Connector on Windows allows an...
Moderate
Unreviewed
CVE-2023-28806
was published
Aug 6, 2024
The Zscaler Updater process does not validate the digital signature of the installer before...
Moderate
Unreviewed
CVE-2024-23460
was published
Aug 6, 2024
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate...
Moderate
Unreviewed
CVE-2024-0567
was published
Jan 16, 2024
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local...
Moderate
Unreviewed
CVE-2024-20892
was published
Jul 2, 2024
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification...
Moderate
Unreviewed
CVE-2024-2307
was published
Mar 19, 2024
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160,...
Moderate
Unreviewed
CVE-2019-5300
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API