GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
157 advisories
Filter by severity
An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary...
Moderate
Unreviewed
CVE-2018-10407
was published
May 14, 2022
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature...
Moderate
Unreviewed
CVE-2018-16150
was published
May 14, 2022
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature...
Moderate
Unreviewed
CVE-2018-16253
was published
May 14, 2022
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x...
Moderate
Unreviewed
CVE-2018-0501
was published
May 14, 2022
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature...
Moderate
Unreviewed
CVE-2018-16149
was published
May 14, 2022
A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019...
Moderate
Unreviewed
CVE-2018-18203
was published
May 14, 2022
GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary...
Moderate
Unreviewed
CVE-2018-15587
was published
May 14, 2022
Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages...
Moderate
Unreviewed
CVE-2018-15586
was published
May 14, 2022
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High...
Moderate
Unreviewed
CVE-2018-5383
was published
May 13, 2022
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an...
Moderate
Unreviewed
CVE-2016-9604
was published
May 13, 2022
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up...
Moderate
Unreviewed
CVE-2017-15090
was published
May 13, 2022
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow...
Moderate
Unreviewed
CVE-2019-1615
was published
May 13, 2022
The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in...
Moderate
Unreviewed
CVE-2018-6459
was published
May 13, 2022
Google Chrome before 17.0.963.46 does not properly check signatures, which allows remote...
Moderate
Unreviewed
CVE-2011-3965
was published
May 13, 2022
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25...
Moderate
Unreviewed
CVE-2014-1498
was published
May 13, 2022
BLS Signature "Malleability"
Moderate
CVE-2021-21405
was published
for
github.com/filecoin-project/lotus
(Go)
May 21, 2021
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue...
Moderate
Unreviewed
CVE-2018-4111
was published
May 13, 2022
Signature validation bypass in ServiceStack
Moderate
CVE-2020-28042
was published
for
ServiceStack
(NuGet)
Jan 13, 2021
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019...
Moderate
Unreviewed
CVE-2018-16042
was published
May 13, 2022
Improper Verification of Cryptographic Signature in keycloak
Moderate
CVE-2019-10201
was published
for
org.keycloak:keycloak-core
(Maven)
Sep 23, 2019
Insufficient consistency checks in signature handling in the networking stack in Google Chrome...
Moderate
Unreviewed
CVE-2017-5066
was published
May 13, 2022
Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function...
Moderate
Unreviewed
CVE-2018-10470
was published
May 13, 2022
A firmware update vulnerability exists in the iburn firmware checks functionality of InHand...
Moderate
Unreviewed
CVE-2022-26510
was published
May 13, 2022
Tendermint light client verification not taking into account chain ID
Moderate
CVE-2022-23507
was published
for
tendermint-light-client
(Rust)
Dec 14, 2022
In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i...
Moderate
Unreviewed
CVE-2020-13101
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API