GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
494 advisories
Filter by severity
A timing side-channel vulnerability has been discovered in the opencryptoki package while...
Moderate
Unreviewed
CVE-2024-0914
was published
Jan 31, 2024
A security vulnerability has been identified in the pkcs11-provider, which is associated with...
High
Unreviewed
CVE-2023-6258
was published
Jan 30, 2024
A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of...
Moderate
Unreviewed
CVE-2024-0564
was published
Jan 30, 2024
An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user...
Moderate
Unreviewed
CVE-2024-22647
was published
Jan 30, 2024
A timing side-channel issue was addressed with improvements to constant-time computation in...
Moderate
Unreviewed
CVE-2024-23218
was published
Jan 23, 2024
Minerva timing attack on P-256 in python-ecdsa
High
CVE-2024-23342
was published
for
ecdsa
(pip)
Jan 22, 2024
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which...
Critical
Unreviewed
CVE-2024-23771
was published
Jan 22, 2024
Marvin Attack of RSA and RSAOAEP decryption in jsrsasign
High
CVE-2024-21484
was published
for
jsrsasign
(npm)
Jan 19, 2024
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK...
Moderate
Unreviewed
CVE-2024-0553
was published
Jan 16, 2024
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
High
CVE-2023-52323
was published
for
pycryptodome
(pip)
Jan 5, 2024
CubeFS timing attack can leak user passwords
High
CVE-2023-46739
was published
for
github.com/cubefs/cubefs
(Go)
Jan 3, 2024
Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1...
Moderate
Unreviewed
CVE-2023-50979
was published
Dec 27, 2023
An Observable Timing Discrepancy, Covert Timing Channel vulnerability in Silabs GSDK on ARM...
Moderate
Unreviewed
CVE-2023-41097
was published
Dec 21, 2023
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This...
Moderate
Unreviewed
CVE-2023-6135
was published
Dec 19, 2023
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an...
Moderate
Unreviewed
CVE-2023-23584
was published
Dec 19, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
Low
CVE-2023-50708
was published
for
yiisoft/yii2-authclient
(Composer)
Dec 18, 2023
The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting...
Moderate
Unreviewed
CVE-2023-4421
was published
Dec 12, 2023
Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant...
High
Unreviewed
CVE-2023-45287
was published
Dec 5, 2023
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation...
Moderate
Unreviewed
CVE-2023-40090
was published
Dec 5, 2023
Marvin Attack: potential key recovery through timing sidechannels
Moderate
CVE-2023-49092
was published
for
rsa
(Rust)
Nov 28, 2023
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK...
High
Unreviewed
CVE-2023-5981
was published
Nov 28, 2023
UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message...
Moderate
Unreviewed
CVE-2023-47102
was published
Nov 13, 2023
In Settings, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21335
was published
Oct 30, 2023
In Text Services, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21333
was published
Oct 30, 2023
In Job Scheduler, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21344
was published
Oct 30, 2023
ProTip!
Advisories are also available from the
GraphQL API