GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,731
Erlang
35
GitHub Actions
29
Go
2,308
Maven
5,000+
npm
3,949
NuGet
711
pip
3,727
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
86 advisories
Filter by severity
"This issue is limited to motherboards and does not affect laptops, desktop computers, or other...
Critical
Unreviewed
CVE-2025-3463
was published
May 9, 2025
Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860...
Critical
Unreviewed
CVE-2024-41334
was published
Feb 27, 2025
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute...
Critical
Unreviewed
CVE-2025-23114
was published
Feb 5, 2025
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An...
Critical
Unreviewed
CVE-2024-52329
was published
Jan 23, 2025
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated...
Critical
Unreviewed
CVE-2024-52330
was published
Jan 23, 2025
An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP...
Critical
Unreviewed
CVE-2019-20461
was published
Nov 7, 2024
An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables...
Critical
Unreviewed
CVE-2024-45159
was published
Sep 5, 2024
There is a vulnerability in the AP Certificate Management Service which could allow a threat...
Critical
Unreviewed
CVE-2024-42395
was published
Aug 6, 2024
In gnss service, there is a possible escalation of privilege due to improper certificate...
Critical
Unreviewed
CVE-2024-20080
was published
Jul 1, 2024
Improper Certificate Validation in apache airflow mongo hook
Critical
CVE-2024-25141
was published
for
apache-airflow-providers-mongo
(pip)
Feb 20, 2024
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under...
Critical
Unreviewed
CVE-2024-25140
was published
Feb 6, 2024
SSL connections to NOVELL and Synology LDAP server are vulnerable to a man-in-the-middle attack...
Critical
Unreviewed
CVE-2023-50356
was published
Jan 31, 2024
Ylianst MeshCentral Missing SSL Certificate Validation
Critical
CVE-2023-51837
was published
for
meshcentral
(npm)
Jan 30, 2024
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2023-42425
was published
Oct 31, 2023
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for...
Critical
Unreviewed
CVE-2023-5422
was published
Oct 16, 2023
Lack of TLS certificate verification in log transmission of a financial module within LINE Client...
Critical
Unreviewed
CVE-2023-5554
was published
Oct 12, 2023
In JetBrains Ktor before 2.3.5 server certificates were not verified
Critical
Unreviewed
CVE-2023-45613
was published
Oct 9, 2023
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed...
Critical
Unreviewed
CVE-2023-40256
was published
Aug 11, 2023
Sydent does not verify email server certificates
Critical
CVE-2023-38686
was published
for
matrix-sydent
(pip)
Jul 31, 2023
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration...
Critical
Unreviewed
CVE-2023-27823
was published
May 12, 2023
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password...
Critical
Unreviewed
CVE-2022-35898
was published
May 1, 2023
Nanoleaf firmware v7.1.1 and below is missing an SSL certificate, allowing attackers to execute...
Critical
Unreviewed
CVE-2022-47758
was published
Apr 27, 2023
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows...
Critical
Unreviewed
CVE-2021-46880
was published
Apr 15, 2023
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable...
Critical
Unreviewed
CVE-2023-26463
was published
Apr 15, 2023
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation.
Critical
Unreviewed
CVE-2022-45597
was published
Mar 25, 2023
ProTip!
Advisories are also available from the
GraphQL API