GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
42
Go
3,124
Maven
5,000+
npm
5,000+
NuGet
826
pip
4,434
Pub
12
RubyGems
988
Rust
1,172
Swift
50
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication
Critical
GHSA-27jc-jmp8-qfw5
was published
for
keylime
(pip)
Feb 6, 2026
•
withdrawn
SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows...
High
Unreviewed
CVE-2025-62501
was published
Feb 3, 2026
A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could...
High
Unreviewed
CVE-2025-20163
was published
Jun 4, 2025
Backup uploads to ETM subject to man-in-the-middle interception
High
Unreviewed
CVE-2024-47519
was published
Jan 11, 2025
A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle...
High
Unreviewed
CVE-2024-7516
was published
Nov 12, 2024
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and...
Moderate
Unreviewed
CVE-2024-6572
was published
Sep 9, 2024
A vulnerability was found in Satellite. When running a remote execution job on a host, the host's...
Moderate
Unreviewed
CVE-2024-4871
was published
May 14, 2024
When matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarder
High
CVE-2022-39254
was published
for
matrix-nio
(pip)
Sep 30, 2022
matrix-js-sdk subject to user impersonation due to key/device identifier confusion in SAS verification
High
CVE-2022-39250
was published
for
matrix-js-sdk
(npm)
Sep 30, 2022
matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion
High
CVE-2022-39248
was published
for
org.matrix.android:matrix-android-sdk2
(Maven)
Sep 30, 2022
matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions
High
CVE-2022-39246
was published
for
org.matrix.android:matrix-android-sdk2
(Maven)
Sep 30, 2022
matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion
High
CVE-2022-39251
was published
for
matrix-js-sdk
(npm)
Sep 30, 2022
Jenkins Git client plugin 3.11.0 does not perform SSH host key verification
Moderate
CVE-2022-36881
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Jul 28, 2022
ProTip!
Advisories are also available from the
GraphQL API