GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
157 advisories
Filter by severity
github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
Moderate
CVE-2020-15216
was published
for
github.com/russellhaering/goxmldsig
(Go)
May 24, 2021
Json-jwt did not verify the cryptographic signature for data
Moderate
CVE-2018-1000539
was published
for
json-jwt
(RubyGems)
Jul 31, 2018
Signature verification failure in Tendermint
Moderate
GHSA-f3w5-v9xx-rp8p
was published
for
github.com/tendermint/tendermint
(Go)
Dec 20, 2021
HTTPS MitM vulnerability due to lack of hostname verification
Moderate
CVE-2016-10932
was published
for
hyper
(Rust)
Aug 25, 2021
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application...
Moderate
Unreviewed
CVE-2023-28818
was published
Mar 24, 2023
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow...
Moderate
Unreviewed
CVE-2019-1808
was published
May 24, 2022
A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco...
Moderate
Unreviewed
CVE-2019-1810
was published
May 24, 2022
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow...
Moderate
Unreviewed
CVE-2019-1809
was published
May 24, 2022
russh may use insecure Diffie-Hellman keys
Moderate
CVE-2023-28113
was published
for
russh
(Rust)
Mar 17, 2023
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all...
Moderate
Unreviewed
CVE-2021-43074
was published
Feb 16, 2023
SIF's Digital Signature Hash Algorithms Not Validated
Moderate
CVE-2022-39237
was published
for
github.com/sylabs/sif/v2
(Go)
Oct 6, 2022
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary...
Moderate
Unreviewed
CVE-2021-3521
was published
Aug 23, 2022
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the...
Moderate
Unreviewed
CVE-2020-10759
was published
May 24, 2022
It was found that Spacewalk, all versions through 2.8, did not safely compute client token...
Moderate
Unreviewed
CVE-2019-10136
was published
May 24, 2022
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain...
Moderate
Unreviewed
CVE-2021-43392
was published
Mar 5, 2022
Missing server signature validation in OctoberCMS
Moderate
CVE-2022-23655
was published
for
october/system
(Composer)
Feb 24, 2022
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse...
Moderate
Unreviewed
CVE-2021-43393
was published
Mar 5, 2022
There is a vulnerability of signature verification mechanism failure in system upgrade through...
Moderate
Unreviewed
CVE-2021-40045
was published
Feb 11, 2022
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan...
Moderate
Unreviewed
CVE-2016-8021
was published
May 17, 2022
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that...
Moderate
Unreviewed
CVE-2021-20156
was published
Dec 31, 2021
FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic...
Moderate
Unreviewed
CVE-2017-8190
was published
May 17, 2022
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to...
Moderate
Unreviewed
CVE-2017-12333
was published
May 17, 2022
Huawei APP HiWallet earlier than 5.0.3.100 versions do not support signature verification for APK...
Moderate
Unreviewed
CVE-2017-8177
was published
May 17, 2022
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on...
Moderate
Unreviewed
CVE-2018-0486
was published
May 14, 2022
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on...
Moderate
Unreviewed
CVE-2018-0489
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API