GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,112
Maven
5,000+
npm
3,767
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
174 advisories
Filter by severity
Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially...
Critical
Unreviewed
CVE-2022-37163
was published
Sep 9, 2022
RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived...
High
Unreviewed
CVE-2012-2441
was published
May 13, 2022
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T...
High
Unreviewed
CVE-2018-6312
was published
May 13, 2022
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong...
Moderate
Unreviewed
CVE-2019-4565
was published
May 24, 2022
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise...
High
Unreviewed
CVE-2018-15766
was published
May 13, 2022
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users...
High
Unreviewed
CVE-2018-1680
was published
May 13, 2022
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by...
High
Unreviewed
CVE-2018-1956
was published
May 13, 2022
Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to...
High
Unreviewed
CVE-2021-40333
was published
Dec 3, 2021
An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7...
Moderate
Unreviewed
CVE-2021-41696
was published
Dec 10, 2021
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords...
High
Unreviewed
CVE-2021-20470
was published
Dec 4, 2021
In Canon LBP223 printers, the System Manager Mode login does not require an account password or...
High
Unreviewed
CVE-2021-43471
was published
Dec 7, 2021
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to...
Critical
Unreviewed
CVE-2019-7674
was published
May 13, 2022
A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port...
High
Unreviewed
CVE-2019-7676
was published
May 13, 2022
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank...
Critical
Unreviewed
CVE-2019-9123
was published
May 13, 2022
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization...
High
Unreviewed
CVE-2018-1101
was published
May 13, 2022
Open Dental before version 18.4 installs a mysql database and uses the default credentials of ...
Critical
Unreviewed
CVE-2018-15719
was published
May 13, 2022
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow...
High
Unreviewed
CVE-2018-0204
was published
May 13, 2022
Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain...
Critical
Unreviewed
CVE-2022-37164
was published
Sep 9, 2022
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity...
High
Unreviewed
CVE-2017-1597
was published
May 13, 2022
A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and...
Critical
Unreviewed
CVE-2017-16727
was published
May 13, 2022
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong...
Critical
Unreviewed
CVE-2017-1196
was published
May 13, 2022
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have...
Critical
Unreviewed
CVE-2017-1221
was published
May 13, 2022
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting...
Critical
Unreviewed
CVE-2017-12861
was published
May 13, 2022
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can...
Critical
Unreviewed
CVE-2017-14189
was published
May 13, 2022
IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant...
Moderate
Unreviewed
CVE-2017-1386
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API