GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,081
Erlang
29
GitHub Actions
19
Go
1,908
Maven
5,000+
npm
3,642
NuGet
638
pip
3,258
Pub
10
RubyGems
869
Rust
820
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
100 advisories
Filter by severity
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5...
Moderate
Unreviewed
CVE-2024-27247
was published
Apr 9, 2024
Improper privilege management in the installer for Zoom Desktop Client for Windows before version...
Moderate
Unreviewed
CVE-2024-24694
was published
Apr 9, 2024
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for...
Moderate
Unreviewed
CVE-2024-27244
was published
May 15, 2024
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated...
Moderate
Unreviewed
CVE-2023-49646
was published
Dec 14, 2023
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables...
Moderate
Unreviewed
CVE-2024-41258
was published
Jul 31, 2024
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey()...
Moderate
Unreviewed
CVE-2024-41254
was published
Jul 31, 2024
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to...
Moderate
Unreviewed
CVE-2024-5912
was published
Jul 10, 2024
An Improper Validation of signature in Zscaler Client Connector on Windows allows an...
Moderate
Unreviewed
CVE-2023-28806
was published
Aug 6, 2024
The Zscaler Updater process does not validate the digital signature of the installer before...
Moderate
Unreviewed
CVE-2024-23460
was published
Aug 6, 2024
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate...
Moderate
Unreviewed
CVE-2024-0567
was published
Jan 16, 2024
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local...
Moderate
Unreviewed
CVE-2024-20892
was published
Jul 2, 2024
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification...
Moderate
Unreviewed
CVE-2024-2307
was published
Mar 19, 2024
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160,...
Moderate
Unreviewed
CVE-2019-5300
was published
May 24, 2022
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird...
Moderate
Unreviewed
CVE-2018-18509
was published
May 24, 2022
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only...
Moderate
Unreviewed
CVE-2018-12556
was published
May 24, 2022
An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on...
Moderate
Unreviewed
CVE-2023-28804
was published
Oct 23, 2023
Improper verification of applications' cryptographic signatures in the /e/OS app store client App...
Moderate
Unreviewed
CVE-2021-43171
was published
Aug 22, 2023
Incorrect signature verification of the firmware during the Device Firmware Update process of...
Moderate
Unreviewed
CVE-2023-33768
was published
Jul 13, 2023
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Improper Verification of...
Moderate
Unreviewed
CVE-2019-3738
was published
May 24, 2022
Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the...
Moderate
Unreviewed
CVE-2019-5592
was published
May 24, 2022
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement...
Moderate
Unreviewed
CVE-2017-18407
was published
May 24, 2022
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client...
Moderate
Unreviewed
CVE-2019-9149
was published
May 24, 2022
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier,...
Moderate
Unreviewed
CVE-2019-8338
was published
May 24, 2022
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu...
Moderate
Unreviewed
CVE-2012-2092
was published
Apr 23, 2022
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the...
Moderate
Unreviewed
CVE-2011-3374
was published
Apr 22, 2022
ProTip!
Advisories are also available from the
GraphQL API