GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,458
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,141
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
42 advisories
Filter by severity
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in...
High
Unreviewed
CVE-2026-59776
was published
Jul 21, 2026
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a...
Moderate
Unreviewed
CVE-2026-58638
was published
Jul 14, 2026
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform...
High
Unreviewed
CVE-2026-55144
was published
Jul 14, 2026
OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
Moderate
CVE-2026-48480
was published
for
io.netty.incubator:netty-incubator-codec-ohttp
(Maven)
Jun 23, 2026
Deno: Miller-Rabin Primality Test Allows Zero Rounds
High
CVE-2026-49440
was published
for
deno
(Rust)
Jun 16, 2026
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux...
High
Unreviewed
CVE-2026-9266
was published
Jun 12, 2026
Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV
(RFC 8452) mishandle the...
Moderate
Unreviewed
CVE-2026-45446
was published
Jun 9, 2026
Issue summary: When an application drives an AES-OCB context through the
public EVP_Cipher() one...
High
Unreviewed
CVE-2026-45445
was published
Jun 9, 2026
Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)
peer key, the peer...
Low
Unreviewed
CVE-2026-42770
was published
Jun 9, 2026
An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client...
Moderate
Unreviewed
CVE-2026-0420
was published
Jun 9, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted...
Moderate
Unreviewed
CVE-2026-29142
was published
Apr 2, 2026
jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction
High
CVE-2026-4601
was published
for
jsrsasign
(npm)
Mar 23, 2026
sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey
High
CVE-2026-4258
was published
for
sjcl
(npm)
Mar 17, 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
High
Unreviewed
CVE-2025-47383
was published
Mar 2, 2026
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware...
Moderate
Unreviewed
CVE-2025-69418
was published
Jan 27, 2026
Deno node:crypto doesn't finalize cipher
Critical
CVE-2026-22863
was published
for
deno
(Rust)
Jan 16, 2026
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2025-60704
was published
Nov 11, 2025
frost-core: refresh shares with smaller min_signers will reduce security of group
Moderate
CVE-2025-58359
was published
for
frost-core
(Rust)
Sep 3, 2025
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash...
Moderate
Unreviewed
CVE-2025-49600
was published
Jul 4, 2025
RLPx 5 has two CTR streams based on the same key, IV, and nonce. This can facilitate decryption...
Low
Unreviewed
CVE-2015-20112
was published
Jun 29, 2025
A vulnerability, which was classified as problematic, has been found in fossasia open-event...
Moderate
Unreviewed
CVE-2025-5323
was published
May 29, 2025
Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX,...
Moderate
Unreviewed
CVE-2025-3938
was published
May 22, 2025
sigstore has insufficient validation of integration timestamp during verification
Low
CVE-2024-55655
was published
for
sigstore
(pip)
Dec 11, 2024
Bit flip attack vulnerability in cookie-encrypter
High
CVE-2024-53441
was published
for
cookie-encrypter
(npm)
Dec 9, 2024
A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for...
Moderate
Unreviewed
CVE-2022-20793
was published
Nov 15, 2024
ProTip!
Advisories are also available from the
GraphQL API