GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,373
Erlang
33
GitHub Actions
22
Go
2,135
Maven
5,000+
npm
3,797
NuGet
687
pip
3,478
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
440 advisories
Filter by severity
The Linux kernel, as used in Ubuntu 18.10 and when booted with UEFI Secure Boot enabled, allows...
High
Unreviewed
CVE-2018-18653
was published
May 13, 2022
Matrix Synapse Improper Signature Validation
High
CVE-2018-16515
was published
for
matrix-synapse
(pip)
May 13, 2022
Missing certificate validation in Apache JMeter
Critical
CVE-2018-1287
was published
for
org.apache.jmeter:ApacheJMeter
(Maven)
May 13, 2022
An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the...
High
Unreviewed
CVE-2018-10988
was published
May 13, 2022
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and...
High
Unreviewed
CVE-2017-6445
was published
May 13, 2022
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10...
Critical
Unreviewed
CVE-2017-2423
was published
May 13, 2022
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2...
High
Unreviewed
CVE-2017-11400
was published
May 13, 2022
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an...
Moderate
Unreviewed
CVE-2016-9604
was published
May 13, 2022
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up...
Moderate
Unreviewed
CVE-2017-15090
was published
May 13, 2022
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the...
Critical
Unreviewed
CVE-2017-3198
was published
May 13, 2022
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an...
High
Unreviewed
CVE-2018-15374
was published
May 13, 2022
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC...
Low
Unreviewed
CVE-2018-1842
was published
May 13, 2022
Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention ...
High
Unreviewed
CVE-2018-6664
was published
May 13, 2022
The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted...
High
Unreviewed
CVE-2018-7685
was published
May 13, 2022
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow...
Moderate
Unreviewed
CVE-2019-1615
was published
May 13, 2022
Improper Verification of Cryptographic Signature in Nimbus JOSE+JWT
High
CVE-2017-12974
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
May 13, 2022
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and...
High
Unreviewed
CVE-2018-16151
was published
May 13, 2022
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and...
High
Unreviewed
CVE-2018-16152
was published
May 13, 2022
The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in...
Moderate
Unreviewed
CVE-2018-6459
was published
May 13, 2022
Google Chrome before 17.0.963.46 does not properly check signatures, which allows remote...
Moderate
Unreviewed
CVE-2011-3965
was published
May 13, 2022
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25...
Moderate
Unreviewed
CVE-2014-1498
was published
May 13, 2022
HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers,...
Critical
Unreviewed
CVE-2019-6318
was published
May 13, 2022
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue...
Moderate
Unreviewed
CVE-2018-4111
was published
May 13, 2022
Cisco node-jose improper validation of JWT signature
High
CVE-2018-0114
was published
for
node-jose
(npm)
May 13, 2022
A vulnerability has been identified in SIMATIC S7-400 (incl. F) V6 and below (All versions),...
High
Unreviewed
CVE-2018-16557
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API