GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
989 advisories
Filter by severity
Certificate length was not properly checked when added to a certificate store. In practice only...
High
Unreviewed
CVE-2025-1014
was published
Feb 4, 2025
HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack
High
CVE-2023-48052
was published
for
httpie
(pip)
Nov 16, 2023
This vulnerability allows network-adjacent attackers to compromise transport security on affected...
Moderate
Unreviewed
CVE-2024-23970
was published
Jan 31, 2025
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password...
Critical
Unreviewed
CVE-2022-35898
was published
May 1, 2023
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
High
CVE-2024-10039
was published
for
org.keycloak:keycloak-core
(Maven)
Nov 25, 2024
Windows Cryptographic Services Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-30020
was published
May 14, 2024
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the...
Moderate
Unreviewed
CVE-2023-38009
was published
Jan 26, 2025
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration...
Critical
Unreviewed
CVE-2023-27823
was published
May 12, 2023
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated...
Critical
Unreviewed
CVE-2024-52330
was published
Jan 23, 2025
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An...
Critical
Unreviewed
CVE-2024-52329
was published
Jan 23, 2025
Agent Dart is missing certificate verification checks
High
CVE-2024-48915
was published
for
agent_dart
(Pub)
Oct 15, 2024
BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can...
Low
Unreviewed
CVE-2024-42186
was published
Jan 23, 2025
Windows Cryptographic Services Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-29050
was published
Apr 9, 2024
An issue in the native clients for Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV...
High
Unreviewed
CVE-2025-0500
was published
Jan 15, 2025
An issue in the native clients for Amazon WorkSpaces Clients when running PCoIP protocol may...
High
Unreviewed
CVE-2025-0501
was published
Jan 15, 2025
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports...
Moderate
Unreviewed
CVE-2023-28321
was published
May 26, 2023
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager ...
Critical
Unreviewed
CVE-2020-27648
was published
May 24, 2022
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH)...
Moderate
Unreviewed
CVE-2024-54847
was published
Jan 10, 2025
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private...
Moderate
Unreviewed
CVE-2024-54849
was published
Jan 10, 2025
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and...
Moderate
Unreviewed
CVE-2024-54846
was published
Jan 10, 2025
Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow...
High
Unreviewed
CVE-2024-54848
was published
Jan 10, 2025
When using Alt-Svc, ALPN did not properly validate certificates when the original server is...
Moderate
Unreviewed
CVE-2025-0239
was published
Jan 7, 2025
A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for...
Moderate
Unreviewed
CVE-2025-20126
was published
Jan 8, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized...
High
Unreviewed
CVE-2024-40702
was published
Jan 7, 2025
ProTip!
Advisories are also available from the
GraphQL API