GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,325
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0...
Moderate
Unreviewed
CVE-2025-33012
was published
Nov 7, 2025
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-48813
was published
Oct 14, 2025
Rejected reason: The original vulnerability was not valid.
Moderate
Unreviewed
CVE-2023-5342
was published
Aug 14, 2025
Keycloaks's One Time Passcode (OTP) is valid longer than expiration timeSeverity
Moderate
CVE-2024-7318
was published
for
org.keycloak:keycloak-core
(Maven)
Oct 14, 2024
Duplicate Advisory: Keycloak Uses a Key Past its Expiration Date
Moderate
GHSA-57rh-gr4v-j5f6
was published
for
org.keycloak:keycloak-core
(Maven)
Sep 9, 2024
•
withdrawn
Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker...
Moderate
Unreviewed
CVE-2024-6299
was published
Jun 25, 2024
Moodle uses the same key for QR login and auto-login
Moderate
CVE-2024-38277
was published
for
moodle/moodle
(Composer)
Jun 18, 2024
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2024-31894
was published
May 22, 2024
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2024-31895
was published
May 22, 2024
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2024-31893
was published
May 22, 2024
In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt...
Moderate
Unreviewed
CVE-2024-25679
was published
Feb 9, 2024
The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x...
Moderate
Unreviewed
CVE-2019-3790
was published
May 24, 2022
Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server
Moderate
CVE-2022-24732
was published
for
github.com/foxcpp/maddy
(Go)
Mar 7, 2022
ProTip!
Advisories are also available from the
GraphQL API