GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,097 advisories
Filter by severity
NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2023-51634
was published
Nov 22, 2024
A flaw was found in the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an...
High
Unreviewed
CVE-2024-8007
was published
Aug 21, 2024
Improper Certificate Validation in Twisted
Critical
CVE-2019-12855
was published
for
twisted
(pip)
Aug 16, 2019
Python Twisted trustRoot is not respected in HTTP client
High
CVE-2014-7143
was published
for
twisted
(pip)
Dec 17, 2019
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software...
Moderate
Unreviewed
CVE-2020-3557
was published
May 24, 2022
python-scciclient vulnerable to Man-in-the-middle (MITM) attacks
Critical
CVE-2022-2996
was published
for
python-scciclient
(pip)
Sep 2, 2022
An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point ...
High
Unreviewed
CVE-2024-45205
was published
Dec 4, 2024
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates...
Moderate
Unreviewed
CVE-2005-3170
was published
May 1, 2022
An improper certificate validation vulnerability has been reported to affect several QNAP...
High
Unreviewed
CVE-2024-48865
was published
Dec 6, 2024
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an...
Low
Unreviewed
CVE-2024-12174
was published
Dec 10, 2024
Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM...
Moderate
Unreviewed
CVE-2024-38861
was published
Sep 27, 2024
lxd CA certificate sign check bypass
Low
CVE-2024-6156
was published
for
github.com/canonical/lxd
(Go)
Dec 9, 2024
An improper validation vulnerability was reported in the firmware update mechanism of LADM and...
High
Unreviewed
CVE-2024-4762
was published
Dec 16, 2024
An improper certificate validation vulnerability was reported in LADM that could allow a network...
High
Unreviewed
CVE-2024-6001
was published
Dec 16, 2024
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a...
Moderate
Unreviewed
CVE-2024-47119
was published
Dec 18, 2024
TCPDF missing certificate validation
High
CVE-2024-56521
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
Active Directory Domain Services Elevation of Privilege Vulnerability.
High
Unreviewed
CVE-2022-26923
was published
May 11, 2022
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized...
High
Unreviewed
CVE-2024-40702
was published
Jan 7, 2025
A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for...
Moderate
Unreviewed
CVE-2025-20126
was published
Jan 8, 2025
When using Alt-Svc, ALPN did not properly validate certificates when the original server is...
Moderate
Unreviewed
CVE-2025-0239
was published
Jan 7, 2025
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and...
Moderate
Unreviewed
CVE-2024-54846
was published
Jan 10, 2025
Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow...
High
Unreviewed
CVE-2024-54848
was published
Jan 10, 2025
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH)...
Moderate
Unreviewed
CVE-2024-54847
was published
Jan 10, 2025
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private...
Moderate
Unreviewed
CVE-2024-54849
was published
Jan 10, 2025
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager ...
Critical
Unreviewed
CVE-2020-27648
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API