GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
487 advisories
Filter by severity
Jenkins NeuVector Vulnerability Scanner Plugin disables SSL/TLS certificate and hostname validation
Moderate
CVE-2023-30517
was published
for
io.jenkins.plugins:neuvector-vulnerability-scanner
(Maven)
Apr 12, 2023
A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All...
Moderate
Unreviewed
CVE-2023-23588
was published
Apr 11, 2023
Improper Certificate Validation in node-sass
Moderate
CVE-2020-24025
was published
for
node-sass
(npm)
Feb 9, 2022
in-toto: PGP trust model not (fully) considered
Moderate
GHSA-jjgp-whrp-gq8m
was published
for
in-toto
(pip)
May 11, 2023
A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted...
Moderate
Unreviewed
CVE-2021-22278
was published
May 24, 2022
Improper Certificate Validation in security-framework
Moderate
CVE-2017-18588
was published
for
security-framework
(Rust)
Aug 25, 2021
Keycloak Untrusted Certificate Validation vulnerability
Moderate
CVE-2023-1664
was published
for
org.keycloak:keycloak-core
(Maven)
Jun 30, 2023
Improper Certificate Validation in Puppet
Moderate
CVE-2020-7942
was published
for
puppet
(RubyGems)
Apr 13, 2021
kevinsawicki/http-request Missing certificate validation
Moderate
CVE-2019-1010206
was published
for
com.github.kevinsawicki:http-request
(Maven)
May 24, 2022
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the...
Moderate
Unreviewed
CVE-2023-1055
was published
Feb 28, 2023
Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by...
Moderate
Unreviewed
CVE-2021-45035
was published
Sep 25, 2022
Pion/DLTS Accepts Client Certificates Without CertificateVerify
Moderate
CVE-2022-29222
was published
for
github.com/pion/dtls
(Go)
May 25, 2022
Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation
Moderate
CVE-2023-25392
was published
for
bigflow
(pip)
Apr 10, 2023
Keycloak Authentication Error
Moderate
CVE-2018-10894
was published
for
org.keycloak:keycloak-saml-adapter-core
(Maven)
May 13, 2022
Jenkins SiteMonitor Plugin globally and unconditionally disables SSL/TLS certificate validation
Moderate
CVE-2019-10317
was published
for
org.jvnet.hudson.plugins:sitemonitor
(Maven)
May 24, 2022
Jenkins Koji Plugin globally and unconditionally disables SSL/TLS certificate validation
Moderate
CVE-2019-10314
was published
for
org.jenkins-ci.plugins:koji
(Maven)
May 24, 2022
Jenkins Bumblebee HP ALM Plugin unconditionally disabled SSL/TLS certificate validation
Moderate
CVE-2019-10444
was published
for
org.jenkins-ci.plugins:bumblebee
(Maven)
May 24, 2022
SSL/TLS certificate validation unconditionally disabled by Jenkins NS-ND Integration Performance Publisher Plugin
Moderate
CVE-2022-38666
was published
for
org.jenkins-ci.main:cavisson-ns-nd-integration
(Maven)
Nov 16, 2022
Jenkins NS-ND Integration Performance Publisher Plugin disables SSL/TLS certificate validation globally and unconditionally
Moderate
CVE-2022-45391
was published
for
io.jenkins.plugins:cavisson-ns-nd-integration
(Maven)
Nov 16, 2022
Bouncy Castle For Java LDAP injection vulnerability
Moderate
CVE-2023-33201
was published
for
org.bouncycastle:bcprov-debug-jdk14
(Maven)
Jul 5, 2023
Jenkins SAML Single Sign On(SSO) Plugin unconditionally disables SSL/TLS certificate validation
Moderate
CVE-2023-32994
was published
for
io.jenkins.plugins:miniorange-saml-sp
(Maven)
May 16, 2023
Summary - The certificate used to identify Orchestrator to EdgeConnect devices is not validated...
Moderate
Unreviewed
CVE-2020-12143
was published
May 24, 2022
Details The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is...
Moderate
Unreviewed
CVE-2020-12144
was published
May 24, 2022
Apache Bookkeeper vulnerable to Improper Certificate Validation
Moderate
CVE-2022-32531
was published
for
org.apache.bookkeeper:bookkeeper-common
(Maven)
Dec 15, 2022
Sensitive information disclosure and manipulation due to improper certification validation. The...
Moderate
Unreviewed
CVE-2022-45457
was published
May 18, 2023
ProTip!
Advisories are also available from the
GraphQL API