GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,205
Erlang
31
GitHub Actions
19
Go
1,988
Maven
5,000+
npm
3,704
NuGet
661
pip
3,332
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
77 advisories
Filter by severity
An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a...
Critical
Unreviewed
CVE-2022-26305
was published
Jul 26, 2022
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL:...
Critical
Unreviewed
CVE-2014-8164
was published
Jul 7, 2022
In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line...
Critical
Unreviewed
CVE-2022-32156
was published
Jun 16, 2022
The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not...
Critical
Unreviewed
CVE-2022-32151
was published
Jun 16, 2022
Couchbase Sync Gateway admin credentials not verified when using X.509 client cert authentication
Critical
CVE-2022-32563
was published
for
couchbase
(pip)
Jun 11, 2022
Improper Certificate Validation in Apache Netbeans
Critical
CVE-2019-17560
was published
for
org.codehaus.mevenide:netbeans
(Maven)
May 24, 2022
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages....
Critical
Unreviewed
CVE-2017-7406
was published
May 24, 2022
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate...
Critical
Unreviewed
CVE-2021-33907
was published
May 24, 2022
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted...
Critical
Unreviewed
CVE-2021-33695
was published
May 24, 2022
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker...
Critical
Unreviewed
CVE-2021-20110
was published
May 24, 2022
While processing server certificate from IPSec server, certificate validation for subject...
Critical
Unreviewed
CVE-2020-11176
was published
May 24, 2022
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of...
Critical
Unreviewed
CVE-2020-28907
was published
May 24, 2022
The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server...
Critical
Unreviewed
CVE-2021-3460
was published
May 24, 2022
DoTls13CertificateVerify in tls13.c in wolfSSL through 4.6.0 does not cease processing for...
Critical
Unreviewed
CVE-2021-3336
was published
May 24, 2022
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM)...
Critical
Unreviewed
CVE-2020-27649
was published
May 24, 2022
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager ...
Critical
Unreviewed
CVE-2020-27648
was published
May 24, 2022
A certificate validation issue existed when processing administrator added certificates. This...
Critical
Unreviewed
CVE-2020-9868
was published
May 24, 2022
Scalyr Agent Missing SSL Certificate Validation
Critical
CVE-2020-24714
was published
for
scalyr-agent-2
(pip)
May 24, 2022
Scalyr Agent 2 Missing SSL Certificate Validation
Critical
CVE-2020-24715
was published
for
scalyr-agent-2
(pip)
May 24, 2022
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c...
Critical
Unreviewed
CVE-2020-7043
was published
May 24, 2022
Keycloak Authentication Error
Critical
CVE-2019-14910
was published
for
org.keycloak:keycloak-parent
(Maven)
May 24, 2022
European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate...
Critical
Unreviewed
CVE-2019-18633
was published
May 24, 2022
European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because...
Critical
Unreviewed
CVE-2019-18632
was published
May 24, 2022
systemd 239 through 243 accepts any certificate signed by a trusted certificate authority for DNS...
Critical
Unreviewed
CVE-2018-21029
was published
May 24, 2022
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via...
Critical
Unreviewed
CVE-2015-2320
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API