GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,480
Maven
5,000+
npm
4,097
NuGet
734
pip
3,910
Pub
12
RubyGems
945
Rust
1,014
Swift
39
Unreviewed advisories
All unreviewed
5,000+
194 advisories
Filter by severity
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption...
High
Unreviewed
CVE-2019-1543
was published
May 13, 2022
An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface...
High
Unreviewed
CVE-2016-8370
was published
May 13, 2022
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3 and RSA BSAFE...
High
Unreviewed
CVE-2015-0535
was published
May 13, 2022
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3 and RSA BSAFE...
High
Unreviewed
CVE-2015-0533
was published
May 13, 2022
The client in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.9 and 4.1.x before 4.1.5...
High
Unreviewed
CVE-2016-0923
was published
May 13, 2022
An exploitable Weak Cryptography for Passwords vulnerability exists in the web server...
High
Unreviewed
CVE-2017-12129
was published
May 13, 2022
IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic...
High
Unreviewed
CVE-2021-20479
was published
May 10, 2022
Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation...
High
Unreviewed
CVE-2007-5460
was published
May 1, 2022
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak...
High
Unreviewed
CVE-2007-4150
was published
May 1, 2022
IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could...
High
Unreviewed
CVE-2021-39082
was published
Apr 30, 2022
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.
High
Unreviewed
CVE-2012-5623
was published
Apr 23, 2022
The Bulletproofs 2017/1066 paper mishandles Fiat-Shamir generation because the hash computation...
High
Unreviewed
CVE-2022-29566
was published
Apr 22, 2022
IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could...
High
Unreviewed
CVE-2021-39076
was published
Apr 20, 2022
Dell PowerScale OneFS, version 9.3.0, contains a use of a broken or risky cryptographic algorithm...
High
Unreviewed
CVE-2022-22559
was published
Apr 13, 2022
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository gnuboard...
High
Unreviewed
CVE-2022-1252
was published
Apr 12, 2022
The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and...
High
Unreviewed
CVE-2021-33018
was published
Apr 3, 2022
IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic...
High
Unreviewed
CVE-2022-22327
was published
Apr 2, 2022
golang.org/x/crypto/ssh Denial of service via crafted Signer
High
CVE-2022-27191
was published
for
golang.org/x/crypto
(Go)
Mar 19, 2022
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure...
High
Unreviewed
CVE-2021-27756
was published
Mar 5, 2022
An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method...
High
Unreviewed
CVE-2020-36516
was published
Feb 27, 2022
Use of a Broken or Risky Cryptographic Algorithm in PostgreSQL
High
Unreviewed
CVE-2020-25694
was published
Feb 15, 2022
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to...
High
Unreviewed
CVE-2021-46559
was published
Jan 27, 2022
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues...
High
Unreviewed
CVE-2021-33846
was published
Jan 22, 2022
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic...
High
Unreviewed
CVE-2021-38921
was published
Jan 11, 2022
Use of a Broken or Risky Cryptographic Algorithm in Max Mazurov Maddy
High
CVE-2021-42583
was published
for
github.com/foxcpp/maddy
(Go)
Jan 6, 2022
ProTip!
Advisories are also available from the
GraphQL API