GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,350
Erlang
31
GitHub Actions
22
Go
2,119
Maven
5,000+
npm
3,778
NuGet
680
pip
3,459
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
83 advisories
Filter by severity
An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible...
Critical
Unreviewed
CVE-2022-34831
was published
Sep 15, 2022
python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
Critical
CVE-2022-2996
was published
for
python-scciclient
(pip)
Sep 2, 2022
When using Ingest Actions to configure a destination that resides on Amazon Simple Storage...
Critical
Unreviewed
CVE-2022-37437
was published
Aug 17, 2022
In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x,...
Critical
Unreviewed
CVE-2022-34865
was published
Aug 5, 2022
fs2-io skips mTLS client verification
Critical
CVE-2022-31183
was published
for
co.fs2:fs2-io
(Maven)
Jul 29, 2022
An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a...
Critical
Unreviewed
CVE-2022-26305
was published
Jul 26, 2022
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL:...
Critical
Unreviewed
CVE-2014-8164
was published
Jul 7, 2022
The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not...
Critical
Unreviewed
CVE-2022-32151
was published
Jun 16, 2022
In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line...
Critical
Unreviewed
CVE-2022-32156
was published
Jun 16, 2022
Couchbase Sync Gateway admin credentials not verified when using X.509 client cert authentication
Critical
CVE-2022-32563
was published
for
couchbase
(pip)
Jun 11, 2022
Improper Certificate Validation in Apache Netbeans
Critical
CVE-2019-17560
was published
for
org.codehaus.mevenide:netbeans
(Maven)
May 24, 2022
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages....
Critical
Unreviewed
CVE-2017-7406
was published
May 24, 2022
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate...
Critical
Unreviewed
CVE-2021-33907
was published
May 24, 2022
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted...
Critical
Unreviewed
CVE-2021-33695
was published
May 24, 2022
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker...
Critical
Unreviewed
CVE-2021-20110
was published
May 24, 2022
While processing server certificate from IPSec server, certificate validation for subject...
Critical
Unreviewed
CVE-2020-11176
was published
May 24, 2022
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of...
Critical
Unreviewed
CVE-2020-28907
was published
May 24, 2022
The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server...
Critical
Unreviewed
CVE-2021-3460
was published
May 24, 2022
DoTls13CertificateVerify in tls13.c in wolfSSL through 4.6.0 does not cease processing for...
Critical
Unreviewed
CVE-2021-3336
was published
May 24, 2022
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM)...
Critical
Unreviewed
CVE-2020-27649
was published
May 24, 2022
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager ...
Critical
Unreviewed
CVE-2020-27648
was published
May 24, 2022
A certificate validation issue existed when processing administrator added certificates. This...
Critical
Unreviewed
CVE-2020-9868
was published
May 24, 2022
Scalyr Agent 2 Missing SSL Certificate Validation
Critical
CVE-2020-24715
was published
for
scalyr-agent-2
(pip)
May 24, 2022
Scalyr Agent Missing SSL Certificate Validation
Critical
CVE-2020-24714
was published
for
scalyr-agent-2
(pip)
May 24, 2022
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c...
Critical
Unreviewed
CVE-2020-7043
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API