GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
487 advisories
Filter by severity
The "Algonquin State Bank Mobile Banking" by Algonquin State Bank app 3.0.0 -- aka algonquin...
Moderate
Unreviewed
CVE-2017-9581
was published
May 17, 2022
The "FSBY Mobile Banking" by First State Bank of Yoakum TX app 3.0.0 -- aka fsby-mobile-banking...
Moderate
Unreviewed
CVE-2017-9586
was published
May 17, 2022
The "Peoples Bank Tulsa" by Peoples Bank - OK app 3.0.2 -- aka peoples-bank-tulsa/id1074279285...
Moderate
Unreviewed
CVE-2017-9600
was published
May 17, 2022
The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates,...
Moderate
Unreviewed
CVE-2015-0904
was published
May 17, 2022
'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server...
Moderate
Unreviewed
CVE-2022-29482
was published
Jun 15, 2022
The RBB SPEED TEST App for Android version 2.0.3 and earlier, RBB SPEED TEST App for iOS version...
Moderate
Unreviewed
CVE-2017-2278
was published
May 17, 2022
An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when...
Moderate
Unreviewed
CVE-2020-36477
was published
May 24, 2022
Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH...
Moderate
Unreviewed
CVE-2021-20989
was published
May 24, 2022
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key...
Moderate
Unreviewed
CVE-2021-34558
was published
May 24, 2022
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept...
Moderate
Unreviewed
CVE-2021-36382
was published
May 24, 2022
An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses...
Moderate
Unreviewed
CVE-2022-26491
was published
Jun 3, 2022
Dell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2.x, 19.2.0.x, 19.2.1.x 19.3.x, 19.3.0...
Moderate
Unreviewed
CVE-2022-29082
was published
May 27, 2022
An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an...
Moderate
Unreviewed
CVE-2020-16197
was published
May 24, 2022
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname...
Moderate
Unreviewed
CVE-2020-13614
was published
May 24, 2022
A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5,...
Moderate
Unreviewed
CVE-2022-26766
was published
May 27, 2022
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and...
Moderate
Unreviewed
CVE-2015-3152
was published
May 14, 2022
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable...
Moderate
Unreviewed
CVE-2022-22946
was published
Mar 5, 2022
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names)...
Moderate
Unreviewed
CVE-2021-44532
was published
Feb 25, 2022
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under...
Moderate
Unreviewed
CVE-2022-25243
was published
Mar 11, 2022
Improper Certificate Validation in Jenkins
Moderate
CVE-2017-1000396
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Improper Certificate Validation in Shibboleth Identity Provider and OpenSAML
Moderate
CVE-2015-1796
was published
for
edu.internet2.middleware:shibboleth-identityprovider
(Maven)
May 17, 2022
Improper Certificate Handling
Moderate
CVE-2020-9321
was published
for
github.com/traefik/traefik
(Go)
Sep 2, 2021
Improper Certificate Validation in OkHttp
Moderate
CVE-2016-2402
was published
for
com.squareup.okhttp3:okhttp
(Maven)
May 13, 2022
An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL...
Moderate
Unreviewed
CVE-2017-2913
was published
May 13, 2022
Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08...
Moderate
Unreviewed
CVE-2021-3898
was published
Apr 23, 2022
ProTip!
Advisories are also available from the
GraphQL API