GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
1,998
Maven
5,000+
npm
3,710
NuGet
661
pip
3,363
Pub
11
RubyGems
885
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
412 advisories
Filter by severity
A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could...
Moderate
Unreviewed
CVE-2021-1461
was published
Nov 18, 2024
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS...
High
Unreviewed
CVE-2024-40592
was published
Nov 12, 2024
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which...
High
Unreviewed
CVE-2024-49393
was published
Nov 12, 2024
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing...
Moderate
Unreviewed
CVE-2024-49394
was published
Nov 12, 2024
Permission control vulnerability in the hidebug module
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2024-51526
was published
Nov 5, 2024
Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations
Low
CVE-2024-51744
was published
for
github.com/golang-jwt/jwt/v4
(Go)
Nov 4, 2024
Laravel Reverb Missing API Signature Verification
High
CVE-2024-50347
was published
for
laravel/reverb
(Composer)
Oct 31, 2024
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE...
Moderate
Unreviewed
CVE-2024-8036
was published
Oct 25, 2024
Agent Dart is missing certificate verification checks
High
CVE-2024-48915
was published
for
agent_dart
(Pub)
Oct 15, 2024
Valid ECDSA signatures erroneously rejected in Elliptic
Low
CVE-2024-48948
was published
for
elliptic
(npm)
Oct 15, 2024
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III...
Unknown
Unreviewed
CVE-2024-47943
was published
Oct 15, 2024
Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak
High
GHSA-xgfv-xpx8-qhcr
was published
for
org.keycloak:keycloak-saml-core
(Maven)
Oct 14, 2024
SSOReady has an XML Signature Bypass via differential XML parsing
Critical
CVE-2024-47832
was published
for
github.com/ssoready/ssoready
(Go)
Oct 11, 2024
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could...
High
Unreviewed
CVE-2024-8531
was published
Oct 11, 2024
An improper verification of cryptographic signature vulnerability was identified in GitHub...
Critical
Unreviewed
CVE-2024-9487
was published
Oct 11, 2024
Elliptic's verify function omits uniqueness validation
Low
CVE-2024-48949
was published
for
elliptic
(npm)
Oct 10, 2024
Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2024-23960
was published
Sep 28, 2024
Improper verification of cryptographic signature during installation of a VPN driver via the...
High
Unreviewed
CVE-2024-7479
was published
Sep 25, 2024
Improper verification of cryptographic signature during installation of a Printer driver via the...
High
Unreviewed
CVE-2024-7481
was published
Sep 25, 2024
Keycloak SAML signature validation flaw
Moderate
CVE-2024-8698
was published
for
org.keycloak:keycloak-saml-core
(Maven)
Sep 19, 2024
druid-pac4j, Apache Druid extension, has Padding Oracle vulnerability
Low
CVE-2024-45384
was published
for
org.apache.druid.extensions:druid-pac4j
(Maven)
Sep 17, 2024
Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document...
High
Unreviewed
CVE-2024-7788
was published
Sep 17, 2024
whatsapp-api-js fails to validate message's signature
Moderate
CVE-2024-45607
was published
for
whatsapp-api-js
(npm)
Sep 12, 2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical
GHSA-cvp8-5r8g-fhvq
was published
for
omniauth-saml
(RubyGems)
Sep 11, 2024
SAML authentication bypass via Incorrect XPath selector
Critical
CVE-2024-45409
was published
for
ruby-saml
(RubyGems)
Sep 10, 2024
ProTip!
Advisories are also available from the
GraphQL API