GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,099 advisories
Filter by severity
Improper Certificate Validation in WP-CLI framework
Critical
CVE-2021-29504
was published
for
wp-cli/wp-cli
(Composer)
May 19, 2021
The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL...
Moderate
Unreviewed
CVE-2011-0199
was published
May 17, 2022
The SSLVerifySignedServerKeyExchange function in libsecurity_ssl/lib/sslKeyExchange.c in the...
Moderate
Unreviewed
CVE-2014-1266
was published
May 14, 2022
Lynx does not verify that the server's certificate is signed by a trusted certification authority...
Moderate
Unreviewed
CVE-2012-5821
was published
May 17, 2022
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and...
Moderate
Unreviewed
CVE-2023-33757
was published
Jan 25, 2024
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate....
Moderate
Unreviewed
CVE-2023-33760
was published
Jan 25, 2024
Improper Certificate Validation in MongoDB
Moderate
CVE-2021-20328
was published
for
org.mongodb:mongo-java-driver
(Maven)
May 24, 2022
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under...
Critical
Unreviewed
CVE-2024-25140
was published
Feb 6, 2024
The Chase mobile banking application for Android does not verify that the server hostname matches...
Moderate
Unreviewed
CVE-2012-5810
was published
May 17, 2022
Improper Input Validation in XFire
High
CVE-2012-5817
was published
for
org.codehaus.xfire:xfire-core
(Maven)
May 17, 2022
An improper certificate validation vulnerability in Fortinet FortiOS 7.0.0 - 7.0.13, 7.2.0 - 7.2...
Moderate
Unreviewed
CVE-2023-47537
was published
Feb 15, 2024
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to...
High
Unreviewed
CVE-2021-22909
was published
May 24, 2022
In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions...
Moderate
Unreviewed
CVE-2023-22943
was published
Feb 14, 2023
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust...
High
Unreviewed
CVE-2002-0862
was published
Apr 30, 2022
Apache Tomcat affected by vulnerability in TLS and SSL protocol
Moderate
CVE-2009-3555
was published
for
org.apache.tomcat:tomcat
(Maven)
May 2, 2022
OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows...
High
Unreviewed
CVE-2010-1378
was published
May 2, 2022
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before...
Moderate
Unreviewed
CVE-2009-2408
was published
May 2, 2022
The contribution feature in Zamboni does not verify that the server hostname matches a domain...
Moderate
Unreviewed
CVE-2012-5822
was published
May 17, 2022
FilesAnywhere does not verify that the server hostname matches a domain name in the subject's...
Moderate
Unreviewed
CVE-2012-5819
was published
May 17, 2022
Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field...
Low
Unreviewed
CVE-2012-2993
was published
May 17, 2022
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle...
Moderate
Unreviewed
CVE-2021-23155
was published
Nov 19, 2021
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Moderate
CVE-2017-0248
was published
for
Microsoft.AspNetCore.Mvc
(NuGet)
Oct 16, 2018
Cloud Foundry vulnerable to Improper Certificate Validation
Moderate
CVE-2016-5016
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 14, 2022
Improper Input Validation in Apache Thrift
High
CVE-2018-1320
was published
for
org.apache.thrift:libthrift
(Maven)
Jan 17, 2019
Improper Certificate Validation in proton-j
High
CVE-2018-17187
was published
for
org.apache.qpid:proton-j
(Maven)
Nov 21, 2018
ProTip!
Advisories are also available from the
GraphQL API