GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,968
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,037
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,117 advisories
Filter by severity
NeuVector telemetry sender is vulnerable to MITM and DoS
High
CVE-2025-54470
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and...
High
Unreviewed
CVE-2025-11619
was published
Oct 15, 2025
GeoIP processor disables SSL certificate validation when downloading databases
Moderate
GHSA-3xgr-h5hq-7299
was published
for
org.opensearch.dataprepper.plugins:geoip-processor
(Maven)
Oct 15, 2025
OpenSearch Data Prepper uses deprecated SSL protocol identifier
Moderate
GHSA-28gg-8qqj-fhh5
was published
for
org.opensearch.dataprepper.plugins:geoip-processor
(Maven)
Oct 15, 2025
go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents
Moderate
CVE-2025-62375
was published
for
github.com/in-toto/go-witness
(Go)
Oct 15, 2025
OpenSearch Data Prepper plugins trust all SSL certificates by default
High
CVE-2025-62371
was published
for
org.opensearch.dataprepper.plugins:opensearch
(Maven)
Oct 15, 2025
A vulnerability was reported in the Lenovo LeCloud client application that, under certain...
Moderate
Unreviewed
CVE-2025-10699
was published
Oct 15, 2025
An improper certificate validation vulnerability was reported in the Lenovo Universal Device...
Low
Unreviewed
CVE-2025-6026
was published
Oct 15, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
High
CVE-2025-11695
was published
for
mongodb
(Rust)
Oct 13, 2025
A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is...
Moderate
Unreviewed
CVE-2025-11633
was published
Oct 12, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
Critical
Unreviewed
CVE-2025-34235
was published
Sep 29, 2025
The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server...
Moderate
Unreviewed
CVE-2025-10548
was published
Sep 23, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and...
Critical
Unreviewed
CVE-2025-34199
was published
Sep 19, 2025
MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates:...
Critical
Unreviewed
CVE-2024-13990
was published
Sep 19, 2025
DragonFly's manager generates mTLS certificates for arbitrary IP addresses
High
CVE-2025-59353
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication
Moderate
CVE-2025-59347
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An...
Low
Unreviewed
CVE-2025-35434
was published
Sep 17, 2025
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
Moderate
CVE-2025-9708
was published
for
KubernetesClient
(NuGet)
Sep 17, 2025
An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0...
Critical
Unreviewed
CVE-2025-55109
was published
Sep 16, 2025
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew...
High
Unreviewed
CVE-2025-50944
was published
Sep 15, 2025
WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle...
Moderate
Unreviewed
CVE-2025-58781
was published
Sep 12, 2025
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a...
High
Unreviewed
CVE-2025-30277
was published
Aug 29, 2025
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a...
High
Unreviewed
CVE-2025-30278
was published
Aug 29, 2025
Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in...
Moderate
Unreviewed
CVE-2025-58123
was published
Aug 28, 2025
Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM...
Moderate
Unreviewed
CVE-2025-58124
was published
Aug 28, 2025
ProTip!
Advisories are also available from the
GraphQL API