GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
157 advisories
Filter by severity
An insufficiently secured internal function allows session generation for arbitrary users. The...
High
Unreviewed
CVE-2025-30064
was published
Aug 27, 2025
A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that...
High
Unreviewed
CVE-2025-4371
was published
Aug 18, 2025
A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0...
High
Unreviewed
CVE-2025-40758
was published
Aug 14, 2025
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly...
High
Unreviewed
CVE-2025-47827
was published
Jun 5, 2025
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker...
High
Unreviewed
CVE-2022-38177
was published
Sep 22, 2022
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker...
High
Unreviewed
CVE-2022-38178
was published
Sep 22, 2022
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions), SiPass...
High
Unreviewed
CVE-2022-31807
was published
May 23, 2025
Insufficient verification of multiple header signatures while loading a Trusted Application (TA)...
High
Unreviewed
CVE-2021-26391
was published
Nov 10, 2022
Improper verification of cryptographic signature in Microsoft Azure Functions allows an...
High
Unreviewed
CVE-2025-33074
was published
Apr 30, 2025
CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution...
High
Unreviewed
CVE-2025-2764
was published
Apr 23, 2025
An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature...
High
Unreviewed
CVE-2017-17848
was published
May 14, 2022
An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI...
High
Unreviewed
CVE-2017-17847
was published
May 14, 2022
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in...
High
Unreviewed
CVE-2017-16853
was published
May 14, 2022
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth...
High
Unreviewed
CVE-2017-16852
was published
May 14, 2022
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and...
High
Unreviewed
CVE-2017-6445
was published
May 13, 2022
MSI Center before 2.0.52.0 has Missing PE Signature Validation.
High
Unreviewed
CVE-2025-27813
was published
Apr 10, 2025
Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass...
High
Unreviewed
CVE-2025-2233
was published
Mar 12, 2025
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has...
High
Unreviewed
CVE-2023-34058
was published
Oct 27, 2023
A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for...
High
Unreviewed
CVE-2025-20206
was published
Mar 5, 2025
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1...
High
Unreviewed
CVE-2024-49413
was published
Dec 3, 2024
When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate...
High
Unreviewed
CVE-2020-2021
was published
May 24, 2022
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A...
High
Unreviewed
CVE-2024-22461
was published
Dec 13, 2024
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and...
High
Unreviewed
CVE-2024-13172
was published
Jan 14, 2025
Windows Cryptographic Services Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-26228
was published
Apr 9, 2024
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted...
High
Unreviewed
CVE-2024-41165
was published
Dec 19, 2024
ProTip!
Advisories are also available from the
GraphQL API