GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,101 advisories
Filter by severity
Legacy Node API Allows Impersonation in github.com/spiffe/spire/pkg/server/endpoints/node
High
CVE-2021-27098
was published
for
github.com/spiffe/spire
(Go)
May 21, 2021
Keycloak Authentication Error
Moderate
CVE-2018-10894
was published
for
org.keycloak:keycloak-saml-adapter-core
(Maven)
May 13, 2022
Jenkins SiteMonitor Plugin globally and unconditionally disables SSL/TLS certificate validation
Moderate
CVE-2019-10317
was published
for
org.jvnet.hudson.plugins:sitemonitor
(Maven)
May 24, 2022
Jenkins Koji Plugin globally and unconditionally disables SSL/TLS certificate validation
Moderate
CVE-2019-10314
was published
for
org.jenkins-ci.plugins:koji
(Maven)
May 24, 2022
Jenkins Bumblebee HP ALM Plugin unconditionally disabled SSL/TLS certificate validation
Moderate
CVE-2019-10444
was published
for
org.jenkins-ci.plugins:bumblebee
(Maven)
May 24, 2022
SSL/TLS certificate validation unconditionally disabled by Jenkins NS-ND Integration Performance Publisher Plugin
Moderate
CVE-2022-38666
was published
for
org.jenkins-ci.main:cavisson-ns-nd-integration
(Maven)
Nov 16, 2022
Jenkins NS-ND Integration Performance Publisher Plugin disables SSL/TLS certificate validation globally and unconditionally
Moderate
CVE-2022-45391
was published
for
io.jenkins.plugins:cavisson-ns-nd-integration
(Maven)
Nov 16, 2022
Bouncy Castle For Java LDAP injection vulnerability
Moderate
CVE-2023-33201
was published
for
org.bouncycastle:bcprov-debug-jdk14
(Maven)
Jul 5, 2023
Improper Certificate Validation in chloride
High
CVE-2018-6517
was published
for
chloride
(RubyGems)
Mar 25, 2019
Jenkins SAML Single Sign On(SSO) Plugin unconditionally disables SSL/TLS certificate validation
Moderate
CVE-2023-32994
was published
for
io.jenkins.plugins:miniorange-saml-sp
(Maven)
May 16, 2023
HTTP::Tiny 0.082, a Perl core module since 5.13.9 and available standalone on CPAN, has an...
Unknown
Unreviewed
CVE-2023-31486
was published
Apr 29, 2023
Details The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is...
Moderate
Unreviewed
CVE-2020-12144
was published
May 24, 2022
Summary - The certificate used to identify Orchestrator to EdgeConnect devices is not validated...
Moderate
Unreviewed
CVE-2020-12143
was published
May 24, 2022
Apache Bookkeeper vulnerable to Improper Certificate Validation
Moderate
CVE-2022-32531
was published
for
org.apache.bookkeeper:bookkeeper-common
(Maven)
Dec 15, 2022
Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients
High
CVE-2023-2422
was published
for
org.keycloak:keycloak-services
(Maven)
Jun 30, 2023
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet...
High
Unreviewed
CVE-2023-31421
was published
Oct 26, 2023
Sensitive information disclosure and manipulation due to improper certification validation. The...
Moderate
Unreviewed
CVE-2022-45458
was published
May 18, 2023
Sensitive information disclosure and manipulation due to improper certification validation. The...
Moderate
Unreviewed
CVE-2022-45457
was published
May 18, 2023
light-oauth2 missing public key verification
Moderate
CVE-2023-31580
was published
for
com.networknt:light-oauth2
(Maven)
Oct 25, 2023
Withdrawn Advisory: Netty-handler does not validate host names by default
Moderate
CVE-2023-4586
was published
for
io.netty:netty-handler
(Maven)
Oct 4, 2023
•
withdrawn
Sydent does not verify email server certificates
Critical
CVE-2023-38686
was published
for
matrix-sydent
(pip)
Jul 31, 2023
Duplicate Advisory: Keycloak vulnerable to untrusted certificate validation
Moderate
GHSA-c892-cwq6-qrqf
was published
for
org.keycloak:keycloak-core
(Maven)
May 26, 2023
•
withdrawn
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote...
High
Unreviewed
CVE-2023-42532
was published
Nov 13, 2023
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on...
Moderate
Unreviewed
CVE-2021-39359
was published
May 24, 2022
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2023-42425
was published
Oct 31, 2023
ProTip!
Advisories are also available from the
GraphQL API