GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,633
Erlang
34
GitHub Actions
25
Go
2,239
Maven
5,000+
npm
3,900
NuGet
701
pip
3,667
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
302 advisories
Filter by severity
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could...
Moderate
Unreviewed
CVE-2025-20178
was published
Apr 16, 2025
MSI Center before 2.0.52.0 has Missing PE Signature Validation.
High
Unreviewed
CVE-2025-27813
was published
Apr 10, 2025
The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter...
Moderate
Unreviewed
CVE-2025-31335
was published
Mar 28, 2025
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local...
Moderate
Unreviewed
CVE-2025-20143
was published
Mar 12, 2025
Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass...
High
Unreviewed
CVE-2025-2233
was published
Mar 12, 2025
A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for...
High
Unreviewed
CVE-2025-20206
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27670
was published
Mar 5, 2025
Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in...
Critical
Unreviewed
CVE-2024-11957
was published
Mar 4, 2025
An improper verification of cryptographic signature vulnerability was identified in GitHub...
Moderate
Unreviewed
CVE-2025-23369
was published
Jan 21, 2025
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and...
High
Unreviewed
CVE-2024-13172
was published
Jan 14, 2025
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned...
Moderate
Unreviewed
CVE-2024-7344
was published
Jan 14, 2025
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted...
High
Unreviewed
CVE-2024-43106
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially...
High
Unreviewed
CVE-2024-39804
was published
Dec 19, 2024
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of...
High
Unreviewed
CVE-2024-41138
was published
Dec 19, 2024
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work...
High
Unreviewed
CVE-2024-41145
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially...
High
Unreviewed
CVE-2024-41159
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted...
High
Unreviewed
CVE-2024-41165
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094...
High
Unreviewed
CVE-2024-42004
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially...
High
Unreviewed
CVE-2024-42220
was published
Dec 19, 2024
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A...
High
Unreviewed
CVE-2024-22461
was published
Dec 13, 2024
This vulnerability exists in the TP-Link Archer C50 due to improper signature verification...
High
Unreviewed
CVE-2024-54126
was published
Dec 5, 2024
Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of...
High
Unreviewed
CVE-2024-47476
was published
Dec 3, 2024
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1...
High
Unreviewed
CVE-2024-49413
was published
Dec 3, 2024
A improper verification of cryptographic signature vulnerability in plugin management in iota C...
Critical
Unreviewed
CVE-2024-52958
was published
Nov 27, 2024
The application failed to account for exceptions thrown by the `loadManifestFromFile` method...
Moderate
Unreviewed
CVE-2024-11696
was published
Nov 26, 2024
ProTip!
Advisories are also available from the
GraphQL API