GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
90 advisories
Filter by severity
An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response...
High
Unreviewed
CVE-2023-26071
was published
Mar 28, 2023
The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation...
High
Unreviewed
CVE-2022-3907
was published
Dec 5, 2022
Jetty vulnerable to exposure of sensitive information due to observable discrepancy
High
CVE-2017-9735
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Oct 19, 2018
Atlantis Events vulnerable to Timing Attack
High
CVE-2022-24912
was published
for
github.com/runatlantis/atlantis
(Go)
Jul 30, 2022
Legion of the Bouncy Castle Java Cryptography API Bleichenbacher Oracle Vulnerability
High
CVE-2007-6721
was published
for
bouncycastle:bcprov-jdk14
(Maven)
May 1, 2022
Observable timing discrepancy in JOpenId
High
CVE-2010-10006
was published
for
org.expressme:JOpenId
(Maven)
Jan 18, 2023
In InputMethod, there is a possible way to determine whether an app is installed, without query...
High
Unreviewed
CVE-2023-21337
was published
Oct 30, 2023
In Package Installer, there is a possible way to determine whether an app is installed, without...
High
Unreviewed
CVE-2023-21324
was published
Oct 30, 2023
In Slice, there is a possible disclosure of installed applications due to side channel...
High
Unreviewed
CVE-2023-21298
was published
Oct 30, 2023
Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant...
High
Unreviewed
CVE-2023-45287
was published
Dec 5, 2023
Minerva timing attack on P-256 in python-ecdsa
High
CVE-2024-23342
was published
for
ecdsa
(pip)
Jan 22, 2024
NVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated...
High
Unreviewed
CVE-2023-25529
was published
Sep 20, 2023
Symfony Http-Kernel has non-constant time comparison in UriSigner
High
CVE-2019-18887
was published
for
symfony/http-kernel
(Composer)
Mar 26, 2022
A security vulnerability has been identified in the pkcs11-provider, which is associated with...
High
Unreviewed
CVE-2023-6258
was published
Jan 30, 2024
Marvin Attack of RSA and RSAOAEP decryption in jsrsasign
High
CVE-2024-21484
was published
for
jsrsasign
(npm)
Jan 19, 2024
IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based...
High
Unreviewed
CVE-2023-32342
was published
May 31, 2023
The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login...
High
Unreviewed
CVE-2023-3604
was published
Aug 21, 2023
IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a...
High
Unreviewed
CVE-2023-33850
was published
Aug 22, 2023
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during...
High
Unreviewed
CVE-2023-36127
was published
Oct 11, 2023
phpMyAdmin Unsafe comparison of XSRF/CSRF token
High
CVE-2016-2041
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with...
High
Unreviewed
CVE-2024-37880
was published
Jun 10, 2024
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when...
High
Unreviewed
CVE-2024-39830
was published
Jul 3, 2024
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK...
High
Unreviewed
CVE-2023-5981
was published
Nov 28, 2023
Apache Pulsar SASL Authentication Provider observable timing discrepancy vulnerability
High
CVE-2023-51437
was published
for
org.apache.pulsar:pulsar-broker-auth-sasl
(Maven)
Feb 7, 2024
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
CVE-2023-50782
was published
for
cryptography
(pip)
Feb 5, 2024
ProTip!
Advisories are also available from the
GraphQL API