GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
539 advisories
Filter by severity
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW...
High
Unreviewed
CVE-2025-12006
was published
Jan 16, 2026
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM...
High
Unreviewed
CVE-2025-12007
was published
Jan 16, 2026
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
High
CVE-2026-22818
was published
for
hono
(npm)
Jan 13, 2026
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass
High
CVE-2026-22817
was published
for
hono
(npm)
Jan 13, 2026
Improper verification of cryptographic signature in Windows Admin Center allows an authorized...
High
Unreviewed
CVE-2026-20965
was published
Jan 13, 2026
Jervis Has a JWT Algorithm Confusion Vulnerability
Moderate
CVE-2025-68925
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary...
Moderate
Unreviewed
CVE-2025-68972
was published
Dec 28, 2025
Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit...
Critical
Unreviewed
CVE-2023-53951
was published
Dec 19, 2025
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing...
Moderate
Unreviewed
CVE-2025-43521
was published
Dec 12, 2025
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing...
Low
Unreviewed
CVE-2025-43522
was published
Dec 12, 2025
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker...
Moderate
Unreviewed
CVE-2025-59803
was published
Dec 11, 2025
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before...
Moderate
Unreviewed
CVE-2025-55311
was published
Dec 11, 2025
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and...
Low
Unreviewed
CVE-2025-64786
was published
Dec 9, 2025
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and...
Low
Unreviewed
CVE-2025-64787
was published
Dec 9, 2025
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0...
Critical
Unreviewed
CVE-2025-59718
was published
Dec 9, 2025
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0,...
Critical
Unreviewed
CVE-2025-59719
was published
Dec 9, 2025
Improper verification of cryptographic signatures in the patch management component of Ivanti...
High
Unreviewed
CVE-2025-13662
was published
Dec 9, 2025
Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validation
Critical
CVE-2025-66568
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Critical
CVE-2025-66567
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
auth0/node-jws Improperly Verifies HMAC Signature
High
CVE-2025-65945
was published
for
jws
(npm)
Dec 4, 2025
XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are...
Critical
Unreviewed
CVE-2025-40934
was published
Nov 27, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
CVE-2025-66016
was published
for
cggmp21
(Rust)
Nov 25, 2025
Babylon's BIP322 signature implementation is not fully compliant to the spec
Moderate
GHSA-xq4h-wqm2-668w
was published
for
github.com/babylonlabs-io/babylon/v4
(Go)
Nov 24, 2025
GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing...
High
Unreviewed
CVE-2025-34324
was published
Nov 18, 2025
ProTip!
Advisories are also available from the
GraphQL API