GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
57 advisories
Filter by severity
Signature Validation Bypass
Critical
GHSA-5684-g483-2249
was published
for
github.com/russellhaering/gosaml2
(Go)
May 24, 2021
Signature Validation Bypass
Critical
GHSA-rrfw-hg9m-j47h
was published
for
github.com/russellhaering/goxmldsig
(Go)
May 24, 2021
Improper Verification of Cryptographic Signature
Critical
GHSA-7r96-8g3x-g36m
was published
for
tenvoy
(npm)
Jun 28, 2021
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus...
Critical
Unreviewed
CVE-2021-37160
was published
May 24, 2022
The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series)...
Critical
Unreviewed
CVE-2022-31206
was published
Jul 27, 2022
The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18...
Critical
Unreviewed
CVE-2022-31207
was published
Jul 27, 2022
FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass...
Critical
Unreviewed
CVE-2020-12676
was published
May 24, 2022
Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082...
Critical
Unreviewed
CVE-2020-27540
was published
May 24, 2022
An improper verification of cryptographic signature vulnerability exists in the Palo Alto...
Critical
Unreviewed
CVE-2021-3033
was published
May 24, 2022
IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and...
Critical
Unreviewed
CVE-2021-20487
was published
May 24, 2022
Improper Verification of Cryptographic Signature in Apache Pulsar in TensorFlow
Critical
CVE-2021-22160
was published
for
org.apache.pulsar:pulsar
(Maven)
Jun 1, 2021
Improper Verification of Cryptographic Signature
Critical
CVE-2021-32685
was published
for
tenvoy
(npm)
Jun 21, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
Critical
CVE-2021-43571
was published
for
starkbank-ecdsa
(npm)
Nov 10, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
Critical
CVE-2021-43569
was published
for
starkbank-ecdsa
(NuGet)
Nov 10, 2021
HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers,...
Critical
Unreviewed
CVE-2019-6318
was published
May 13, 2022
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the...
Critical
Unreviewed
CVE-2017-3198
was published
May 13, 2022
acryl-datahub missing JWT signature check
Critical
CVE-2022-39366
was published
for
acryl-datahub
(pip)
Oct 31, 2022
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10...
Critical
Unreviewed
CVE-2017-2423
was published
May 13, 2022
Missing certificate validation in Apache JMeter
Critical
CVE-2018-1287
was published
for
org.apache.jmeter:ApacheJMeter
(Maven)
May 13, 2022
An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2....
Critical
Unreviewed
CVE-2018-12356
was published
May 14, 2022
In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet...
Critical
Unreviewed
CVE-2018-5923
was published
May 14, 2022
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine...
Critical
Unreviewed
CVE-2018-8955
was published
May 14, 2022
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon...
Critical
Unreviewed
CVE-2017-18146
was published
May 14, 2022
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature...
Critical
Unreviewed
CVE-2022-23334
was published
Jan 30, 2023
ProTip!
Advisories are also available from the
GraphQL API