GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
Devolutions.XTS.NET Vulnerable to Timing Attack on GF Multiplications
Moderate
CVE-2024-11862
was published
for
Devolutions.XTS.NET
(NuGet)
Nov 27, 2024
RSA decryption vulnerable to Bleichenbacher timing vulnerability
High
CVE-2020-25659
was published
for
cryptography
(pip)
Oct 27, 2020
Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked...
High
Unreviewed
CVE-2023-46809
was published
Sep 7, 2024
An issue was discovered in Matrix libolm (aka Olm) through 3.2.16. Cache-timing attacks can occur...
High
Unreviewed
CVE-2024-45192
was published
Aug 22, 2024
Observable Timing Discrepancy in pypqc
High
GHSA-hvh4-5qr6-3v7r
was published
for
pypqc
(pip)
Jun 5, 2024
Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA)...
Low
Unreviewed
CVE-2023-33855
was published
Mar 26, 2024
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A...
Moderate
Unreviewed
CVE-2024-25964
was published
Mar 25, 2024
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite,...
Critical
Unreviewed
CVE-2020-35166
was published
Jul 12, 2022
Minerva timing attack on P-256 in python-ecdsa
High
CVE-2024-23342
was published
for
ecdsa
(pip)
Jan 22, 2024
Covert Timing Channel in Apache CXF
High
CVE-2017-3156
was published
for
org.apache.cxf.karaf:apache-cxf
(Maven)
May 13, 2022
Marvin Attack: potential key recovery through timing sidechannels
Moderate
CVE-2023-49092
was published
for
rsa
(Rust)
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
Moderate
GHSA-4grx-2x9w-596c
was published
for
rsa
(Rust)
Nov 28, 2023
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user...
Moderate
Unreviewed
CVE-2016-7056
was published
May 13, 2022
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen...
Moderate
Unreviewed
CVE-2018-10844
was published
May 13, 2022
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM...
Moderate
Unreviewed
CVE-2018-10846
was published
May 13, 2022
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen...
Moderate
Unreviewed
CVE-2018-10845
was published
May 13, 2022
A flaw was found in all released versions of m2crypto, where they are vulnerable to...
Moderate
Unreviewed
CVE-2020-25657
was published
May 24, 2022
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can...
Moderate
Unreviewed
CVE-2020-14341
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API