GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
194 advisories
Filter by severity
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2017-1664
was published
May 14, 2022
SimpleSAMLphp Incorrect IV generation for encryption
Moderate
CVE-2017-12871
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 17, 2022
An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and...
Moderate
Unreviewed
CVE-2017-2391
was published
May 17, 2022
IBM BigFix Compliance Analytics 1.9.79 uses weaker than expected cryptographic algorithms that...
Moderate
Unreviewed
CVE-2017-1179
was published
May 17, 2022
Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the...
Moderate
Unreviewed
CVE-2016-10104
was published
May 17, 2022
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue...
Moderate
Unreviewed
CVE-2016-4685
was published
May 17, 2022
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information,...
Moderate
Unreviewed
CVE-2016-3034
was published
May 17, 2022
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software...
Moderate
Unreviewed
CVE-2015-8085
was published
May 17, 2022
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software...
Moderate
Unreviewed
CVE-2015-8086
was published
May 17, 2022
Beaker Sensitive Information Disclosure vulnerability
Moderate
CVE-2012-3458
was published
for
beaker
(pip)
May 17, 2022
Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through...
Moderate
Unreviewed
CVE-2020-16235
was published
May 20, 2022
Use of a Broken or Risky Cryptographic Algorithm in XWiki Crypto API
Moderate
CVE-2022-29161
was published
for
org.xwiki.platform:xwiki-platform-crypto
(Maven)
May 24, 2022
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2019-4151
was published
May 24, 2022
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses...
Moderate
Unreviewed
CVE-2019-4102
was published
May 24, 2022
In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values...
Moderate
Unreviewed
CVE-2019-10638
was published
May 24, 2022
In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub...
Moderate
Unreviewed
CVE-2019-14664
was published
May 24, 2022
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it...
Moderate
Unreviewed
CVE-2019-15947
was published
May 24, 2022
A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle...
Moderate
Unreviewed
CVE-2019-1338
was published
May 24, 2022
The Infinite Design application 3.4.12 for Android sends a username and password via TCP without...
Moderate
Unreviewed
CVE-2019-17356
was published
May 24, 2022
An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation...
Moderate
Unreviewed
CVE-2019-17428
was published
May 24, 2022
The Bitwarden server through 1.32.0 has a potentially unwanted KDF.
Moderate
Unreviewed
CVE-2019-19766
was published
May 24, 2022
An issue existed in the handling of links in encrypted PDFs. This issue was addressed by adding a...
Moderate
Unreviewed
CVE-2019-8772
was published
May 24, 2022
An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an...
Moderate
Unreviewed
CVE-2019-19891
was published
May 24, 2022
A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR...
Moderate
Unreviewed
CVE-2019-19299
was published
May 24, 2022
A flaw was found in the way certificate signatures could be forged using collisions found in the...
Moderate
Unreviewed
CVE-2019-14855
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API