GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,134
Erlang
30
GitHub Actions
19
Go
1,941
Maven
5,000+
npm
3,681
NuGet
650
pip
3,299
Pub
11
RubyGems
878
Rust
830
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
262 advisories
Filter by severity
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III...
Unknown
Unreviewed
CVE-2024-47943
was published
Oct 15, 2024
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could...
High
Unreviewed
CVE-2024-8531
was published
Oct 11, 2024
An improper verification of cryptographic signature vulnerability was identified in GitHub...
Critical
Unreviewed
CVE-2024-9487
was published
Oct 11, 2024
Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2024-23960
was published
Sep 28, 2024
Improper verification of cryptographic signature during installation of a VPN driver via the...
High
Unreviewed
CVE-2024-7479
was published
Sep 25, 2024
Improper verification of cryptographic signature during installation of a Printer driver via the...
High
Unreviewed
CVE-2024-7481
was published
Sep 25, 2024
Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document...
High
Unreviewed
CVE-2024-7788
was published
Sep 17, 2024
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when...
Critical
Unreviewed
CVE-2024-6800
was published
Aug 20, 2024
Anti-tampering can be disabled under certain conditions without signature validation. This...
High
Unreviewed
CVE-2024-23456
was published
Aug 6, 2024
An Improper Validation of signature in Zscaler Client Connector on Windows allows an...
Moderate
Unreviewed
CVE-2023-28806
was published
Aug 6, 2024
The Zscaler Updater process does not validate the digital signature of the installer before...
Moderate
Unreviewed
CVE-2024-23460
was published
Aug 6, 2024
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey()...
Moderate
Unreviewed
CVE-2024-41254
was published
Jul 31, 2024
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables...
Moderate
Unreviewed
CVE-2024-41258
was published
Jul 31, 2024
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to...
Moderate
Unreviewed
CVE-2024-5912
was published
Jul 10, 2024
Windows Enroll Engine Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-38069
was published
Jul 9, 2024
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x...
High
Unreviewed
CVE-2023-34435
was published
Jul 8, 2024
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local...
Moderate
Unreviewed
CVE-2024-20892
was published
Jul 2, 2024
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an...
High
Unreviewed
CVE-2024-37532
was published
Jun 20, 2024
Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client"...
Critical
Unreviewed
CVE-2024-36277
was published
Jun 17, 2024
There is a possible escalation of privilege due to improperly used crypto. This could lead to...
Critical
Unreviewed
CVE-2024-32911
was published
Jun 13, 2024
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows...
Unknown
Unreviewed
CVE-2024-1721
was published
May 21, 2024
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for...
Moderate
Unreviewed
CVE-2024-27244
was published
May 15, 2024
Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege...
High
Unreviewed
CVE-2023-50228
was published
May 3, 2024
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This...
High
Unreviewed
CVE-2024-23480
was published
May 1, 2024
Improper privilege management in the installer for Zoom Desktop Client for Windows before version...
Moderate
Unreviewed
CVE-2024-24694
was published
Apr 9, 2024
ProTip!
Advisories are also available from the
GraphQL API