GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
487 advisories
Filter by severity
Sensitive information disclosure and manipulation due to improper certification validation. The...
Moderate
Unreviewed
CVE-2022-45458
was published
May 18, 2023
Sensitive information disclosure and manipulation due to improper certification validation. The...
Moderate
Unreviewed
CVE-2022-45457
was published
May 18, 2023
light-oauth2 missing public key verification
Moderate
CVE-2023-31580
was published
for
com.networknt:light-oauth2
(Maven)
Oct 25, 2023
Withdrawn Advisory: Netty-handler does not validate host names by default
Moderate
CVE-2023-4586
was published
for
io.netty:netty-handler
(Maven)
Oct 4, 2023
•
withdrawn
Duplicate Advisory: Keycloak vulnerable to untrusted certificate validation
Moderate
GHSA-c892-cwq6-qrqf
was published
for
org.keycloak:keycloak-core
(Maven)
May 26, 2023
•
withdrawn
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on...
Moderate
Unreviewed
CVE-2021-39359
was published
May 24, 2022
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports...
Moderate
Unreviewed
CVE-2023-28321
was published
May 26, 2023
Jenkins ElectricFlow Plugin globally and unconditionally disabled SSL/TLS certificate validation
Moderate
CVE-2019-10334
was published
for
org.jenkins-ci.plugins:electricflow
(Maven)
May 24, 2022
SSL/TLS certificate validation unconditionally disabled by Jenkins Micro Focus Application Automation Tools Plugin
Moderate
CVE-2021-22511
was published
for
org.jenkins-ci.plugins:hp-application-automation-tools-plugin
(Maven)
May 24, 2022
Improper Validation of Certificate with Host Mismatch in Jenkins Mailer Plugin
Moderate
CVE-2020-2252
was published
for
org.jenkins-ci.plugins:mailer
(Maven)
May 24, 2022
Missing hostname validation in Email Extension Plugin
Moderate
CVE-2020-2253
was published
for
org.jenkins-ci.plugins:email-ext
(Maven)
May 24, 2022
Jenkins vSphere Plugin disables SSL/TLS certificate validation by default
Moderate
CVE-2018-1000151
was published
for
org.jenkins-ci.plugins:vsphere-cloud
(Maven)
May 14, 2022
Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
Moderate
CVE-2020-2187
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
Improper Certificate Validation in Apache CXF
Moderate
CVE-2017-5653
was published
for
org.apache.cxf:cxf-core
(Maven)
May 13, 2022
An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to...
Moderate
Unreviewed
CVE-2023-50454
was published
Dec 10, 2023
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
Moderate
CVE-2023-51662
was published
for
Snowflake.Data
(NuGet)
Dec 22, 2023
If the Node.js https API was used incorrectly and "undefined" was in passed for the ...
Moderate
Unreviewed
CVE-2021-22939
was published
May 24, 2022
Jenkins Git client plugin 3.11.0 does not perform SSH host key verification
Moderate
CVE-2022-36881
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Jul 28, 2022
A certificate validation issue was addressed. This issue is fixed in iOS 16.7 and iPadOS 16.7, OS...
Moderate
Unreviewed
CVE-2023-41991
was published
Sep 21, 2023
Jenkins SSH Build Agents Plugin did not verify host keys
Moderate
CVE-2017-2648
was published
for
org.jenkins-ci.plugins:ssh-slaves
(Maven)
May 13, 2022
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name...
Moderate
Unreviewed
CVE-2023-28807
was published
Jan 31, 2024
X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker...
Moderate
Unreviewed
CVE-2020-7922
was published
May 24, 2022
The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate...
Moderate
Unreviewed
CVE-2023-0466
was published
Mar 28, 2023
Applications that use a non-default option when verifying certificates may be vulnerable to an...
Moderate
Unreviewed
CVE-2023-0465
was published
Mar 28, 2023
IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products...
Moderate
Unreviewed
CVE-2023-47700
was published
Feb 7, 2024
ProTip!
Advisories are also available from the
GraphQL API