GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,164
Erlang
30
GitHub Actions
19
Go
1,973
Maven
5,000+
npm
3,695
NuGet
654
pip
3,312
Pub
11
RubyGems
881
Rust
831
Swift
35
Unreviewed advisories
All unreviewed
5,000+
951 advisories
Filter by severity
HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
Moderate
Unreviewed
CVE-2024-30149
was published
Oct 31, 2024
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the...
Moderate
Unreviewed
CVE-2024-43177
was published
Oct 22, 2024
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper...
Moderate
Unreviewed
CVE-2024-47241
was published
Oct 18, 2024
A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality...
High
Unreviewed
CVE-2023-49570
was published
Oct 18, 2024
A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality...
High
Unreviewed
CVE-2023-6055
was published
Oct 18, 2024
A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality...
High
Unreviewed
CVE-2023-6057
was published
Oct 18, 2024
A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality...
High
Unreviewed
CVE-2023-6056
was published
Oct 18, 2024
A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections. The...
High
Unreviewed
CVE-2023-6058
was published
Oct 18, 2024
A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning...
High
Unreviewed
CVE-2023-49567
was published
Oct 18, 2024
An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass...
Moderate
Unreviewed
CVE-2024-31955
was published
Oct 15, 2024
Agent Dart is missing certificate verification checks
High
CVE-2024-48915
was published
for
agent_dart
(Pub)
Oct 15, 2024
Windows Secure Channel Spoofing Vulnerability
High
Unreviewed
CVE-2024-43550
was published
Oct 8, 2024
SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS...
High
Unreviewed
CVE-2024-7206
was published
Oct 8, 2024
A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could...
Moderate
Unreviewed
CVE-2024-20385
was published
Oct 2, 2024
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
Moderate
Unreviewed
CVE-2024-9160
was published
Sep 27, 2024
Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM...
Moderate
Unreviewed
CVE-2024-38861
was published
Sep 27, 2024
Rancher agents can be hijacked by taking over the Rancher Server URL
High
CVE-2024-22030
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2024
The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially...
Moderate
Unreviewed
CVE-2024-30134
was published
Sep 26, 2024
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server...
Moderate
Unreviewed
CVE-2024-38324
was published
Sep 25, 2024
The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024...
High
Unreviewed
CVE-2024-43201
was published
Sep 23, 2024
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS...
High
Unreviewed
CVE-2024-8287
was published
Sep 18, 2024
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP...
Moderate
Unreviewed
CVE-2024-8096
was published
Sep 11, 2024
AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7...
Moderate
Unreviewed
CVE-2024-31489
was published
Sep 10, 2024
An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions...
Moderate
Unreviewed
CVE-2022-45856
was published
Sep 10, 2024
Httpful is Missing Certificate Validation
Moderate
GHSA-gcfg-hmwx-wq5h
was published
for
nategood/httpful
(Composer)
Sep 9, 2024
ProTip!
Advisories are also available from the
GraphQL API