GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,904
Erlang
38
GitHub Actions
38
Go
2,566
Maven
5,000+
npm
4,237
NuGet
753
pip
4,001
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
122 advisories
Filter by severity
OpenZeppelin Contracts using MerkleProof multiproofs may allow proving arbitrary leaves for specific trees
Moderate
CVE-2023-34459
was published
for
@openzeppelin/contracts
(npm)
Jun 19, 2023
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a...
High
Unreviewed
CVE-2022-45142
was published
Mar 7, 2023
A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic....
Moderate
Unreviewed
CVE-2016-15028
was published
Mar 12, 2023
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update...
Moderate
Unreviewed
CVE-2023-23119
was published
Feb 2, 2023
Improper Validation of Integrity Check Value in go-tuf
High
CVE-2022-29173
was published
for
github.com/theupdateframework/go-tuf
(Go)
May 24, 2022
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can...
Moderate
Unreviewed
CVE-2022-45191
was published
Feb 8, 2023
There is an improper integrity checking vulnerability on some huawei products. The software of...
Low
Unreviewed
CVE-2020-1879
was published
May 24, 2022
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP...
Moderate
Unreviewed
CVE-2021-3772
was published
Mar 4, 2022
FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux...
High
Unreviewed
CVE-2022-36174
was published
Sep 13, 2022
OpenZeppelin Contracts vulnerable to ECDSA signature malleability
High
CVE-2022-35961
was published
for
@openzeppelin/contracts
(npm)
Aug 18, 2022
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full...
High
Unreviewed
CVE-2022-29549
was published
Aug 19, 2022
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity...
Moderate
Unreviewed
CVE-2017-9498
was published
May 13, 2022
The Lenovo Service Framework Android application uses a set of nonsecure credentials when...
High
Unreviewed
CVE-2017-3760
was published
May 13, 2022
An issue was discovered in Listary through 6. Improper implementation of the update process leads...
High
Unreviewed
CVE-2021-41067
was published
Dec 15, 2021
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration...
Critical
Unreviewed
CVE-2022-29898
was published
May 12, 2022
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF,...
Moderate
Unreviewed
CVE-2022-25946
was published
May 6, 2022
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to...
Moderate
Unreviewed
CVE-2021-22276
was published
May 24, 2022
There is an Improper Validation of Integrity Check Value Vulnerability in Huawei Smartphone...
High
Unreviewed
CVE-2021-22442
was published
May 24, 2022
IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local...
High
Unreviewed
CVE-2020-4610
was published
May 24, 2022
The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed...
High
Unreviewed
CVE-2022-22781
was published
Apr 29, 2022
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi...
Moderate
Unreviewed
CVE-2020-26141
was published
May 24, 2022
Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers...
High
Unreviewed
CVE-2021-25388
was published
May 24, 2022
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during...
High
Unreviewed
CVE-2021-31913
was published
May 24, 2022
Proofpoint Enterprise Protection (PPS/PoD) before 8.17.0 contains a vulnerability that could...
Moderate
Unreviewed
CVE-2020-14009
was published
May 24, 2022
Improper validation of integrity check value vulnerability in NEC Aterm WF1200CR firmware Ver1.3...
High
Unreviewed
CVE-2021-20709
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API