GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,850
Maven
5,000+
npm
4,485
NuGet
779
pip
4,238
Pub
12
RubyGems
975
Rust
1,093
Swift
48
Unreviewed advisories
All unreviewed
5,000+
244 advisories
Filter by severity
sm-crypto Affected by Signature Forgery in SM2-DSA
High
CVE-2026-23965
was published
for
sm-crypto
(npm)
Jan 21, 2026
sm-crypto Affected by Signature Malleability in SM2-DSA
High
CVE-2026-23967
was published
for
sm-crypto
(npm)
Jan 21, 2026
IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper...
High
Unreviewed
CVE-2025-36418
was published
Jan 20, 2026
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW...
High
Unreviewed
CVE-2025-12006
was published
Jan 16, 2026
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM...
High
Unreviewed
CVE-2025-12007
was published
Jan 16, 2026
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
High
CVE-2026-22818
was published
for
hono
(npm)
Jan 13, 2026
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass
High
CVE-2026-22817
was published
for
hono
(npm)
Jan 13, 2026
Improper verification of cryptographic signature in Windows Admin Center allows an authorized...
High
Unreviewed
CVE-2026-20965
was published
Jan 13, 2026
GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing...
High
Unreviewed
CVE-2025-34324
was published
Nov 18, 2025
coreos-installer improperly verifies GPG signature when decompressing gzipped artifact
High
CVE-2021-20319
was published
for
coreos-installer
(Rust)
Oct 12, 2021
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing...
High
Unreviewed
CVE-2025-43468
was published
Nov 4, 2025
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions), SiPass...
High
Unreviewed
CVE-2022-31807
was published
May 23, 2025
Improper verification of cryptographic signatures in the patch management component of Ivanti...
High
Unreviewed
CVE-2025-13662
was published
Dec 9, 2025
auth0/node-jws Improperly Verifies HMAC Signature
High
CVE-2025-65945
was published
for
jws
(npm)
Dec 4, 2025
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and...
High
Unreviewed
CVE-2018-16151
was published
May 13, 2022
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and...
High
Unreviewed
CVE-2018-16152
was published
May 13, 2022
Constellation has insecure LUKS2 persistent storage partitions which may be opened and used
High
CVE-2025-58356
was published
for
github.com/edgelesssys/constellation/v2
(Go)
Oct 27, 2025
Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted Enclaves
High
CVE-2025-64186
was published
for
github.com/evervault/evervault-go
(Go)
Nov 12, 2025
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client...
High
Unreviewed
CVE-2025-64740
was published
Nov 13, 2025
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows...
High
Unreviewed
CVE-2025-64456
was published
Nov 10, 2025
Improper authentication in the API authentication middleware of HCL DevOps Loop allows...
High
Unreviewed
CVE-2025-55278
was published
Nov 6, 2025
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the...
High
Unreviewed
CVE-2020-10126
was published
May 24, 2022
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x...
High
Unreviewed
CVE-2023-34435
was published
Jul 8, 2024
CPAN 2.28 allows Signature Verification Bypass.
High
Unreviewed
CVE-2020-16156
was published
Dec 14, 2021
Authlib has algorithm confusion with asymmetric public keys
High
CVE-2024-37568
was published
for
authlib
(pip)
Jun 9, 2024
ProTip!
Advisories are also available from the
GraphQL API