GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,476
Erlang
33
GitHub Actions
24
Go
2,207
Maven
5,000+
npm
3,858
NuGet
696
pip
3,639
Pub
12
RubyGems
913
Rust
918
Swift
38
Unreviewed advisories
All unreviewed
5,000+
441 advisories
Filter by severity
The use of a weak cryptographic key pair in the signature verification process in WPS Office ...
Critical
Unreviewed
CVE-2025-2516
was published
Mar 27, 2025
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could...
Moderate
Unreviewed
CVE-2022-43922
was published
Feb 1, 2023
In the ownCloud application before 2.15 for Android, the lock protection mechanism can be...
Moderate
Unreviewed
CVE-2020-36250
was published
May 24, 2022
Driver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a...
High
Unreviewed
CVE-2022-43460
was published
Feb 13, 2023
A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as...
Low
Unreviewed
CVE-2025-2349
was published
Mar 17, 2025
Jenkins Subversion Plugin Stores Credentials with Base64 Encoding
Moderate
CVE-2013-6372
was published
for
org.jenkins-ci.plugins:subversion
(Maven)
May 17, 2022
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC...
High
Unreviewed
CVE-2024-54089
was published
Feb 11, 2025
Electra Central AC unit – The unit opens an AP with an easily calculated password.
Moderate
Unreviewed
CVE-2023-24502
was published
Jul 6, 2023
The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa...
High
Unreviewed
CVE-2024-29950
was published
Apr 17, 2024
When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0...
High
Unreviewed
CVE-2024-29969
was published
Apr 19, 2024
Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not...
Moderate
Unreviewed
CVE-2024-29951
was published
Apr 17, 2024
Apache Tomcat - XSS in generated JSPs
Moderate
CVE-2024-52318
was published
for
org.apache.tomcat:tomcat-jasper
(Maven)
Nov 18, 2024
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard...
High
Unreviewed
CVE-2023-30351
was published
May 10, 2023
Apache Tomcat Request and/or response mix-up
Moderate
CVE-2024-52317
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Nov 18, 2024
In multiple places of AccessibilityService, there is a possible way to hide the app from the user...
High
Unreviewed
CVE-2023-21109
was published
May 16, 2023
Inadequate Encryption Strength
Critical
CVE-2017-1000486
was published
for
org.primefaces:primefaces
(Maven)
Jun 3, 2021
Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more...
Moderate
Unreviewed
CVE-2024-13454
was published
Jan 20, 2025
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify®...
Moderate
Unreviewed
CVE-2024-13026
was published
Jan 17, 2025
magic-crypt uses insecure cryptographic algorithms
Low
GHSA-gmx7-gr5q-85w5
was published
for
magic-crypt
(Rust)
Dec 30, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app...
High
Unreviewed
CVE-2023-32414
was published
Jun 23, 2023
Moodle uses the same key for QR login and auto-login
Moderate
CVE-2024-38277
was published
for
moodle/moodle
(Composer)
Jun 18, 2024
Portainer improperly uses an encryption algorithm in the AesEncrypt function
High
CVE-2024-33662
was published
for
github.com/portainer/portainer
(Go)
Oct 2, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1
Low
CVE-2024-45719
was published
for
github.com/apache/incubator-answer
(Go)
Nov 22, 2024
An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it...
Moderate
Unreviewed
CVE-2023-37301
was published
Jun 30, 2023
A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software...
High
Unreviewed
CVE-2020-3549
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API