GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
487 advisories
Filter by severity
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6...
Moderate
Unreviewed
CVE-2023-34410
was published
Jun 5, 2023
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all...
Moderate
Unreviewed
CVE-2023-29175
was published
Jun 13, 2023
Jiyu Kukan Toku-Toku coupon App for iOS versions 3.5.0 and earlier, and Jiyu Kukan Toku-Toku...
Moderate
Unreviewed
CVE-2023-29501
was published
Jun 13, 2023
An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows...
Moderate
Unreviewed
CVE-2023-24461
was published
Jul 6, 2023
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6...
Moderate
Unreviewed
CVE-2022-22305
was published
Sep 1, 2023
Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14...
Moderate
Unreviewed
CVE-2023-41180
was published
Sep 3, 2023
Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying...
Moderate
Unreviewed
CVE-2023-35845
was published
Sep 11, 2023
MiniTool Power Data Recovery 11.5 contains an insecure in-app payment system that allows...
Moderate
Unreviewed
CVE-2023-38353
was published
Sep 19, 2023
IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a...
Moderate
Unreviewed
CVE-2022-43892
was published
Oct 17, 2023
OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows...
Moderate
Unreviewed
CVE-2022-3761
was published
Oct 17, 2023
IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to...
Moderate
Unreviewed
CVE-2023-50949
was published
Apr 11, 2024
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity...
Moderate
Unreviewed
CVE-2022-22380
was published
Oct 17, 2023
Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01...
Moderate
Unreviewed
CVE-2023-23901
was published
May 10, 2023
Mercurial Improper Certificate Validation vulnerability
Moderate
CVE-2010-4237
was published
for
mercurial
(pip)
Apr 21, 2022
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
Moderate
CVE-2013-2255
was published
for
cinder
(pip)
May 5, 2022
curl inadvertently kept the SSL session ID for connections in its cache even when the verify...
Moderate
Unreviewed
CVE-2024-0853
was published
Feb 3, 2024
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may...
Moderate
Unreviewed
CVE-2024-33612
was published
May 8, 2024
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper...
Moderate
Unreviewed
CVE-2024-35299
was published
May 16, 2024
Duplicate Advisory: TLS certificate validation error in mellium.im/xmpp
Moderate
GHSA-m658-p24x-p74r
was published
for
mellium.im/xmpp
(Go)
Feb 12, 2022
•
withdrawn
Improper Validation of Certificate with Host Mismatch in mellium.im/xmpp/websocket
Moderate
CVE-2022-24968
was published
for
mellium.im/xmpp
(Go)
Feb 16, 2022
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is...
Moderate
Unreviewed
CVE-2024-25053
was published
Jun 29, 2024
MongoDB Tools Improper Certificate Validation vulnerability
Moderate
CVE-2020-7924
was published
for
github.com/mongodb/mongo-tools
(Go)
May 24, 2022
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used...
Moderate
Unreviewed
CVE-2024-0042
was published
May 7, 2024
An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7...
Moderate
Unreviewed
CVE-2023-50179
was published
Jul 9, 2024
An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0...
Moderate
Unreviewed
CVE-2024-33509
was published
Jul 9, 2024
ProTip!
Advisories are also available from the
GraphQL API