GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
432 advisories
Filter by severity
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to...
Critical
Unreviewed
CVE-2017-14090
was published
May 14, 2022
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2017-1664
was published
May 14, 2022
In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android,...
High
Unreviewed
CVE-2018-5298
was published
May 14, 2022
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2018-1425
was published
May 14, 2022
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for...
Moderate
Unreviewed
CVE-2015-4953
was published
May 14, 2022
IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores...
High
Unreviewed
CVE-2017-1701
was published
May 14, 2022
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker...
High
Unreviewed
CVE-2017-1473
was published
May 14, 2022
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected...
High
Unreviewed
CVE-2017-1255
was published
May 14, 2022
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash...
Moderate
Unreviewed
CVE-2014-0841
was published
May 14, 2022
Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version ...
Critical
Unreviewed
CVE-2018-15124
was published
May 14, 2022
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10...
High
Unreviewed
CVE-2016-4693
was published
May 14, 2022
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the...
Moderate
Unreviewed
CVE-2016-6225
was published
May 14, 2022
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption...
High
Unreviewed
CVE-2017-13699
was published
May 14, 2022
Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum,...
Critical
Unreviewed
CVE-2018-7242
was published
May 14, 2022
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow...
High
Unreviewed
CVE-2018-1648
was published
May 14, 2022
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining...
High
Unreviewed
CVE-2013-7469
was published
May 14, 2022
Using remote content in encrypted messages can lead to the disclosure of plaintext. This...
High
Unreviewed
CVE-2018-5184
was published
May 14, 2022
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2017-1665
was published
May 14, 2022
System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with...
High
Unreviewed
CVE-2018-6635
was published
May 13, 2022
comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL...
Moderate
Unreviewed
CVE-2018-6653
was published
May 13, 2022
Weak Cryptography in PHP-Proxy
High
CVE-2018-19784
was published
for
athlon1600/php-proxy
(Composer)
May 13, 2022
Apache OpenMeetings has Inadequate Encryption Strength
Critical
CVE-2017-7673
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
May 13, 2022
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue...
Moderate
Unreviewed
CVE-2017-2399
was published
May 13, 2022
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account...
High
Unreviewed
CVE-2017-14262
was published
May 13, 2022
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in...
Critical
Unreviewed
CVE-2017-16726
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API