GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
157 advisories
Filter by severity
Improper Verification of Cryptographic Signature in aws-encryption-sdk-java
Moderate
CVE-2024-23680
was published
for
com.amazonaws:aws-encryption-sdk-java
(Maven)
Jan 19, 2024
Adyen APIs Library for Python timing attack vulnerability
Moderate
GHSA-f3q4-ggfp-jv34
was published
for
Adyen
(pip)
Aug 30, 2024
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables...
Moderate
Unreviewed
CVE-2024-41258
was published
Jul 31, 2024
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to...
Moderate
Unreviewed
CVE-2024-5912
was published
Jul 10, 2024
An Improper Validation of signature in Zscaler Client Connector on Windows allows an...
Moderate
Unreviewed
CVE-2023-28806
was published
Aug 6, 2024
The Zscaler Updater process does not validate the digital signature of the installer before...
Moderate
Unreviewed
CVE-2024-23460
was published
Aug 6, 2024
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate...
Moderate
Unreviewed
CVE-2024-0567
was published
Jan 16, 2024
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local...
Moderate
Unreviewed
CVE-2024-20892
was published
Jul 2, 2024
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Moderate
CVE-2022-23540
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
Denial of Service in TenderMint
Moderate
CVE-2020-15091
was published
for
github.com/tendermint/tendermint
(Go)
Dec 20, 2021
A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification...
Moderate
Unreviewed
CVE-2024-2307
was published
Mar 19, 2024
Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature
Moderate
CVE-2022-36056
was published
for
github.com/sigstore/cosign
(Go)
Sep 16, 2022
go-saml's XML Digital Signatures use SHA-1
Moderate
CVE-2020-36563
was published
for
github.com/RobotsAndPencils/go-saml
(Go)
Dec 28, 2022
TYPO3 vulnerable to an Uncontrolled Resource Consumption in the ShowImageController
Moderate
CVE-2024-34358
was published
for
typo3/cms-core
(Composer)
May 14, 2024
Improper Verification of Cryptographic Signature in org.apache.httpcomponents:httpclient
Moderate
CVE-2014-3577
was published
for
org.apache.httpcomponents:httpclient
(Maven)
Oct 17, 2018
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160,...
Moderate
Unreviewed
CVE-2019-5300
was published
May 24, 2022
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird...
Moderate
Unreviewed
CVE-2018-18509
was published
May 24, 2022
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only...
Moderate
Unreviewed
CVE-2018-12556
was published
May 24, 2022
An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on...
Moderate
Unreviewed
CVE-2023-28804
was published
Oct 23, 2023
Improper verification of applications' cryptographic signatures in the /e/OS app store client App...
Moderate
Unreviewed
CVE-2021-43171
was published
Aug 22, 2023
Incorrect signature verification of the firmware during the Device Firmware Update process of...
Moderate
Unreviewed
CVE-2023-33768
was published
Jul 13, 2023
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Improper Verification of...
Moderate
Unreviewed
CVE-2019-3738
was published
May 24, 2022
Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the...
Moderate
Unreviewed
CVE-2019-5592
was published
May 24, 2022
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement...
Moderate
Unreviewed
CVE-2017-18407
was published
May 24, 2022
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client...
Moderate
Unreviewed
CVE-2019-9149
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API