GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,463
Erlang
33
GitHub Actions
22
Go
2,161
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
908
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
372 advisories
Filter by severity
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an...
Moderate
Unreviewed
CVE-2025-0149
was published
Mar 11, 2025
Vela Server Has Insufficient Webhook Payload Data Verification
High
CVE-2025-27616
was published
for
github.com/go-vela/server
(Go)
Mar 10, 2025
Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1944
was published
for
picklescan
(pip)
Mar 10, 2025
Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1945
was published
for
picklescan
(pip)
Mar 10, 2025
Duplicate Advisory: Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-2fh4-gpch-vqv4
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Duplicate Advisory: Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-w6mr-mj53-x258
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices...
Moderate
Unreviewed
CVE-2025-27257
was published
Mar 10, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442...
Critical
Unreviewed
CVE-2025-27680
was published
Mar 5, 2025
Insufficient verification of data authenticity in some Intel(R) DSA software before version 23.4...
High
Unreviewed
CVE-2024-39805
was published
Feb 13, 2025
Hickory DNS failure to verify self-signed RRSIG for DNSKEYs
Moderate
GHSA-v7pc-74h8-xq2h
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Hickory DNS's DNSSEC validation may accept broken authentication chains
Moderate
CVE-2025-25188
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This...
High
Unreviewed
CVE-2025-1108
was published
Feb 7, 2025
An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access...
Low
Unreviewed
CVE-2025-23415
was published
Feb 5, 2025
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid...
Moderate
Unreviewed
CVE-2025-0510
was published
Feb 4, 2025
There is a vulnerability in the BMC firmware image authentication design
at Supermicro MBD...
High
Unreviewed
CVE-2024-10237
was published
Feb 4, 2025
CometBFT allows a malicious peer to stall the network by disseminating seemingly valid block parts
High
GHSA-r3r4-g7hq-pq4f
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2024-54111
was published
Dec 12, 2024
WildFly Elytron OpenID Connect Client Extension authorization code injection attack
Moderate
CVE-2024-12369
was published
for
org.wildfly:wildfly-elytron-oidc-client-subsystem
(Maven)
Dec 9, 2024
An attacker who can execute arbitrary Operating Systems commands, can bypass code signing...
Moderate
Unreviewed
CVE-2024-52548
was published
Dec 3, 2024
quic-go affected by an ICMP Packet Too Large Injection Attack on Linux
Moderate
CVE-2024-53259
was published
for
github.com/quic-go/quic-go
(Go)
Dec 2, 2024
sigstore-java has vulnerability with bundle verification
Moderate
CVE-2024-53267
was published
for
dev.sigstore:sigstore-java
(Maven)
Nov 26, 2024
IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a...
Moderate
Unreviewed
CVE-2022-33861
was published
Nov 25, 2024
OpenStack Neutron can use an incorrect ID during policy enforcement
Moderate
CVE-2024-53916
was published
for
neutron
(pip)
Nov 25, 2024
Affected devices beacon to eCharge cloud infrastructure asking if there are any command they...
Critical
Unreviewed
CVE-2024-11666
was published
Nov 25, 2024
ProTip!
Advisories are also available from the
GraphQL API