GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,679
Erlang
34
GitHub Actions
26
Go
2,268
Maven
5,000+
npm
3,923
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
468 advisories
Filter by severity
Insufficient verification of multiple header signatures while loading a Trusted Application (TA)...
High
Unreviewed
CVE-2021-26391
was published
Nov 10, 2022
Improper verification of cryptographic signature in Microsoft Azure Functions allows an...
High
Unreviewed
CVE-2025-33074
was published
Apr 30, 2025
Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF...
Low
Unreviewed
CVE-2025-2866
was published
Apr 27, 2025
CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution...
High
Unreviewed
CVE-2025-2764
was published
Apr 23, 2025
CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution...
Moderate
Unreviewed
CVE-2025-2763
was published
Apr 23, 2025
An issue in code signature validation was addressed with improved checks. This issue is fixed in...
Moderate
Unreviewed
CVE-2022-42793
was published
Nov 2, 2022
An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature...
High
Unreviewed
CVE-2017-17848
was published
May 14, 2022
An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI...
High
Unreviewed
CVE-2017-17847
was published
May 14, 2022
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth...
High
Unreviewed
CVE-2017-16852
was published
May 14, 2022
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in...
High
Unreviewed
CVE-2017-16853
was published
May 14, 2022
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and...
High
Unreviewed
CVE-2017-6445
was published
May 13, 2022
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan...
Moderate
Unreviewed
CVE-2016-8021
was published
May 17, 2022
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures...
Moderate
Unreviewed
CVE-2025-43903
was published
Apr 18, 2025
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could...
Moderate
Unreviewed
CVE-2025-20178
was published
Apr 16, 2025
MSI Center before 2.0.52.0 has Missing PE Signature Validation.
High
Unreviewed
CVE-2025-27813
was published
Apr 10, 2025
MinIO performs incomplete signature validation for unsigned-trailer uploads
High
CVE-2025-31489
was published
for
github.com/minio/minio
(Go)
Apr 4, 2025
The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter...
Moderate
Unreviewed
CVE-2025-31335
was published
Mar 28, 2025
Signature forgery in Spring Boot's Loader
High
CVE-2024-38807
was published
for
org.springframework.boot:spring-boot-loader
(Maven)
Aug 23, 2024
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade...
Critical
Unreviewed
CVE-2021-36226
was published
Feb 6, 2023
Vulnerability of package name verification being bypassed in the HwIms module.
Impact: Successful...
Critical
Unreviewed
CVE-2023-52538
was published
Apr 8, 2024
Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)
Critical
CVE-2025-25292
was published
for
ruby-saml
(RubyGems)
Mar 12, 2025
Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)
Critical
CVE-2025-25291
was published
for
ruby-saml
(RubyGems)
Mar 12, 2025
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III...
Critical
Unreviewed
CVE-2024-47943
was published
Oct 15, 2024
xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment
Critical
CVE-2025-29775
was published
for
xml-crypto
(npm)
Mar 14, 2025
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
Critical
CVE-2025-29774
was published
for
xml-crypto
(npm)
Mar 14, 2025
ProTip!
Advisories are also available from the
GraphQL API