GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,130 advisories
Filter by severity
Podman Improper Certificate Validation; machine missing TLS verification
High
CVE-2025-6032
was published
for
github.com/containers/podman/v4
(Go)
Jun 25, 2025
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of...
Moderate
Unreviewed
CVE-2016-9064
was published
May 14, 2022
Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a...
Low
Unreviewed
CVE-2025-12893
was published
Nov 25, 2025
A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4...
High
Unreviewed
CVE-2025-44018
was published
Nov 24, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy...
Low
Unreviewed
CVE-2025-65083
was published
Nov 17, 2025
Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10...
Low
Unreviewed
CVE-2025-60022
was published
Nov 17, 2025
pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification
High
CVE-2025-12765
was published
for
pgadmin4
(pip)
Nov 13, 2025
Square OkHttp can accept the wrong certificate
High
CVE-2021-0341
was published
for
com.squareup.okhttp3:okhttp
(Maven)
May 24, 2022
Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to...
Moderate
Unreviewed
CVE-2025-30669
was published
Nov 13, 2025
A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser...
High
Unreviewed
CVE-2025-10495
was published
Nov 12, 2025
A vulnerability was reported in the Lenovo Scanner pro application during an internal security...
Moderate
Unreviewed
CVE-2025-12047
was published
Nov 12, 2025
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11)....
High
Unreviewed
CVE-2025-40744
was published
Nov 11, 2025
Improper certificate
validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream...
Moderate
Unreviewed
CVE-2025-12943
was published
Nov 11, 2025
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data...
High
Unreviewed
CVE-2025-64685
was published
Nov 10, 2025
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate...
Moderate
Unreviewed
CVE-2025-32989
was published
Jul 10, 2025
Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate...
Critical
Unreviewed
CVE-2025-56231
was published
Nov 5, 2025
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
Moderate
CVE-2025-9708
was published
for
KubernetesClient
(NuGet)
Sep 17, 2025
This issue was addressed through improved state management. This issue is fixed in Safari 17.4,...
Moderate
Unreviewed
CVE-2024-23273
was published
Mar 8, 2024
A certificate validation issue was addressed. This issue is fixed in iOS 16.7 and iPadOS 16.7, OS...
Moderate
Unreviewed
CVE-2023-41991
was published
Sep 21, 2023
An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP...
Critical
Unreviewed
CVE-2019-20461
was published
Nov 7, 2024
When using Alt-Svc, ALPN did not properly validate certificates when the original server is...
Moderate
Unreviewed
CVE-2025-0239
was published
Jan 7, 2025
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is...
Moderate
Unreviewed
CVE-2024-25053
was published
Jun 29, 2024
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to...
High
Unreviewed
CVE-2024-31871
was published
Apr 10, 2024
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
High
Unreviewed
CVE-2023-31484
was published
Apr 29, 2023
ProTip!
Advisories are also available from the
GraphQL API