GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
189 advisories
Filter by severity
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS...
High
Unreviewed
CVE-2024-40592
was published
Nov 12, 2024
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which...
High
Unreviewed
CVE-2024-49393
was published
Nov 12, 2024
Permission control vulnerability in the hidebug module
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2024-51526
was published
Nov 5, 2024
Laravel Reverb Missing API Signature Verification
High
CVE-2024-50347
was published
for
laravel/reverb
(Composer)
Oct 31, 2024
Agent Dart is missing certificate verification checks
High
CVE-2024-48915
was published
for
agent_dart
(Pub)
Oct 15, 2024
Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak
High
GHSA-xgfv-xpx8-qhcr
was published
for
org.keycloak:keycloak-saml-core
(Maven)
Oct 14, 2024
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could...
High
Unreviewed
CVE-2024-8531
was published
Oct 11, 2024
Improper verification of cryptographic signature during installation of a VPN driver via the...
High
Unreviewed
CVE-2024-7479
was published
Sep 25, 2024
Improper verification of cryptographic signature during installation of a Printer driver via the...
High
Unreviewed
CVE-2024-7481
was published
Sep 25, 2024
Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document...
High
Unreviewed
CVE-2024-7788
was published
Sep 17, 2024
Hyperledger Indy's update process of a DID does not check who signs the request
High
CVE-2020-11093
was published
for
indy-node
(pip)
Aug 30, 2024
Signature forgery in Spring Boot's Loader
High
CVE-2024-38807
was published
for
org.springframework.boot:spring-boot-loader
(Maven)
Aug 23, 2024
Anti-tampering can be disabled under certain conditions without signature validation. This...
High
Unreviewed
CVE-2024-23456
was published
Aug 6, 2024
Windows Enroll Engine Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-38069
was published
Jul 9, 2024
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x...
High
Unreviewed
CVE-2023-34435
was published
Jul 8, 2024
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an...
High
Unreviewed
CVE-2024-37532
was published
Jun 20, 2024
Authlib has algorithm confusion with asymmetric public keys
High
CVE-2024-37568
was published
for
authlib
(pip)
Jun 9, 2024
Grafana Plugin signature bypass
High
CVE-2022-31123
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege...
High
Unreviewed
CVE-2023-50228
was published
May 3, 2024
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This...
High
Unreviewed
CVE-2024-23480
was published
May 1, 2024
Secure Boot Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-26194
was published
Apr 9, 2024
google-oauth-java-client improperly verifies cryptographic signature
High
CVE-2021-22573
was published
for
com.google.oauth-client:google-oauth-client
(Maven)
Apr 9, 2024
An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware...
High
Unreviewed
CVE-2023-52043
was published
Apr 4, 2024
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent...
High
Unreviewed
CVE-2024-1149
was published
Feb 8, 2024
Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent...
High
Unreviewed
CVE-2024-1150
was published
Feb 8, 2024
ProTip!
Advisories are also available from the
GraphQL API