GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,474
Erlang
33
GitHub Actions
24
Go
2,198
Maven
5,000+
npm
3,843
NuGet
696
pip
3,632
Pub
12
RubyGems
911
Rust
912
Swift
38
Unreviewed advisories
All unreviewed
5,000+
374 advisories
Filter by severity
Insufficient verification of data authenticity in
the configuration state machine may allow a...
Low
Unreviewed
CVE-2023-20570
was published
Feb 13, 2024
Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1944
was published
for
picklescan
(pip)
Mar 10, 2025
A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified...
Moderate
Unreviewed
CVE-2025-2346
was published
Mar 16, 2025
Vela Server Has Insufficient Webhook Payload Data Verification
High
CVE-2025-27616
was published
for
github.com/go-vela/server
(Go)
Mar 10, 2025
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count...
High
Unreviewed
CVE-2024-37370
was published
Jun 29, 2024
Jenkins does not Verify Checksums for Plugin Files
High
CVE-2015-7539
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices...
Moderate
Unreviewed
CVE-2025-27257
was published
Mar 10, 2025
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an...
Moderate
Unreviewed
CVE-2025-0149
was published
Mar 11, 2025
Unitronics Unistream Unilogic – Versions prior to 1.35.227 -
CWE-348: Use of Less Trusted Source...
High
Unreviewed
CVE-2024-27773
was published
Mar 18, 2024
Duplicate Advisory: Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-2fh4-gpch-vqv4
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1945
was published
for
picklescan
(pip)
Mar 10, 2025
Duplicate Advisory: Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-w6mr-mj53-x258
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442...
Critical
Unreviewed
CVE-2025-27680
was published
Mar 5, 2025
Insufficient Verification of Data Authenticity vulnerability in Mitsubishi Electric Corporation...
Critical
Unreviewed
CVE-2023-4699
was published
Nov 6, 2023
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or...
Low
Unreviewed
CVE-2024-10977
was published
Nov 14, 2024
Certifi removes GLOBALTRUST root certificate
Low
CVE-2024-39689
was published
for
certifi
(pip)
Jul 5, 2024
Insufficient verification of data authenticity in some Intel(R) DSA software before version 23.4...
High
Unreviewed
CVE-2024-39805
was published
Feb 13, 2025
Removal of e-Tugra root certificate
High
CVE-2023-37920
was published
for
certifi
(pip)
Jul 25, 2023
Certifi removing TrustCor root certificate
Moderate
CVE-2022-23491
was published
for
certifi
(pip)
Dec 7, 2022
Moodle vulnerable to cache poisoning via injection into storage
Moderate
CVE-2024-43428
was published
for
moodle/moodle
(Composer)
Nov 7, 2024
Hickory DNS failure to verify self-signed RRSIG for DNSKEYs
Moderate
GHSA-v7pc-74h8-xq2h
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Hickory DNS's DNSSEC validation may accept broken authentication chains
Moderate
CVE-2025-25188
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This...
High
Unreviewed
CVE-2025-1108
was published
Feb 7, 2025
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid...
Moderate
Unreviewed
CVE-2025-0510
was published
Feb 4, 2025
An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access...
Low
Unreviewed
CVE-2025-23415
was published
Feb 5, 2025
ProTip!
Advisories are also available from the
GraphQL API