GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,076
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
187 advisories
Filter by severity
Use of Hard-coded Credentials in Apache Kylin
High
CVE-2021-45458
was published
for
org.apache.kylin:kylin
(Maven)
Jan 8, 2022
Reversible One-Way Hash in io.github.javaezlib:JavaEZ
High
CVE-2022-29249
was published
for
io.github.javaezlib:JavaEZ
(Maven)
May 25, 2022
Apache OpenOffice supports the storage of passwords for web connections in the user's...
High
Unreviewed
CVE-2022-37400
was published
Aug 16, 2022
Apache OpenOffice supports the storage of passwords for web connections in the user's...
High
Unreviewed
CVE-2022-37401
was published
Aug 16, 2022
The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the...
High
Unreviewed
CVE-2022-0828
was published
Apr 12, 2022
The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which...
High
Unreviewed
CVE-2022-2083
was published
Sep 6, 2022
An unauthorized user with network access and the decryption key could decrypt sensitive data,...
High
Unreviewed
CVE-2022-38469
was published
Jan 18, 2023
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
High
Unreviewed
CVE-2021-27885
was published
May 24, 2022
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
High
Unreviewed
CVE-2021-31898
was published
May 24, 2022
In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.
High
Unreviewed
CVE-2021-45484
was published
Dec 26, 2021
esptool allows attackers to view sensitive information via weak cryptographic algorithm
High
CVE-2023-46894
was published
for
esptool
(pip)
Nov 9, 2023
Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions
High
CVE-2022-45379
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Nov 16, 2022
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net:...
High
Unreviewed
CVE-2021-32066
was published
May 24, 2022
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000...
High
Unreviewed
CVE-2023-20185
was published
Jul 12, 2023
This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm ...
High
Unreviewed
CVE-2024-1224
was published
Mar 6, 2024
This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic...
High
Unreviewed
CVE-2024-25102
was published
Mar 6, 2024
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector...
High
Unreviewed
CVE-2020-11877
was published
May 24, 2022
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak...
High
Unreviewed
CVE-2012-2130
was published
Apr 23, 2022
IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that...
High
Unreviewed
CVE-2018-2007
was published
May 24, 2022
IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected...
High
Unreviewed
CVE-2018-1608
was published
May 24, 2022
The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the...
High
Unreviewed
CVE-2019-20138
was published
May 24, 2022
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform ...
High
Unreviewed
CVE-2019-13539
was published
May 24, 2022
Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote...
High
Unreviewed
CVE-2023-27389
was published
Apr 11, 2023
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard...
High
Unreviewed
CVE-2023-30351
was published
May 10, 2023
Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40...
High
Unreviewed
CVE-2022-4048
was published
May 15, 2023
ProTip!
Advisories are also available from the
GraphQL API