GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
518 advisories
Filter by severity
XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are...
Critical
Unreviewed
CVE-2025-40934
was published
Nov 27, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
CVE-2025-66016
was published
for
cggmp21
(Rust)
Nov 25, 2025
Babylon's BIP322 signature implementation is not fully compliant to the spec
Moderate
GHSA-xq4h-wqm2-668w
was published
for
github.com/babylonlabs-io/babylon/v4
(Go)
Nov 24, 2025
GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing...
High
Unreviewed
CVE-2025-34324
was published
Nov 18, 2025
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client...
High
Unreviewed
CVE-2025-64740
was published
Nov 13, 2025
Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted Enclaves
High
CVE-2025-64186
was published
for
github.com/evervault/evervault-go
(Go)
Nov 12, 2025
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows...
High
Unreviewed
CVE-2025-64456
was published
Nov 10, 2025
Improper authentication in the API authentication middleware of HCL DevOps Loop allows...
High
Unreviewed
CVE-2025-55278
was published
Nov 6, 2025
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing...
High
Unreviewed
CVE-2025-43468
was published
Nov 4, 2025
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing...
Moderate
Unreviewed
CVE-2025-43390
was published
Nov 4, 2025
Cryptographic validation of upgrade images could be circumventing by dropping a specifically...
Moderate
Unreviewed
CVE-2025-54549
was published
Oct 30, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
Moderate
GHSA-f5p4-p5q5-jv3h
was published
for
github.com/edgelesssys/contrast
(Go)
Oct 28, 2025
A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function...
Moderate
Unreviewed
CVE-2025-12295
was published
Oct 27, 2025
Constellation has insecure LUKS2 persistent storage partitions which may be opened and used
High
CVE-2025-58356
was published
for
github.com/edgelesssys/constellation/v2
(Go)
Oct 27, 2025
Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or...
High
Unreviewed
CVE-2025-34503
was published
Oct 25, 2025
gnark-crypto doesn't range check input values during ECDSA and EdDSA signature deserialization
Moderate
GHSA-fr8m-434r-g3xp
was published
for
github.com/consensys/gnark-crypto
(Go)
Oct 15, 2025
Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate
High
CVE-2025-59288
was published
for
playwright
(npm)
Oct 14, 2025
An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS...
High
Unreviewed
CVE-2025-46774
was published
Oct 14, 2025
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper...
Critical
Unreviewed
CVE-2025-9485
was published
Oct 4, 2025
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned....
High
Unreviewed
CVE-2025-52550
was published
Oct 1, 2025
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW...
Moderate
Unreviewed
CVE-2025-7937
was published
Sep 19, 2025
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM...
Moderate
Unreviewed
CVE-2025-6198
was published
Sep 19, 2025
A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated...
Moderate
Unreviewed
CVE-2025-20248
was published
Sep 10, 2025
An insufficiently secured internal function allows session generation for arbitrary users. The...
High
Unreviewed
CVE-2025-30064
was published
Aug 27, 2025
gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks
High
CVE-2025-57801
was published
for
github.com/consensys/gnark
(Go)
Aug 22, 2025
ProTip!
Advisories are also available from the
GraphQL API