GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
433 advisories
Filter by severity
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user...
Low
Unreviewed
CVE-2002-1739
was published
Apr 30, 2022
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users...
Moderate
Unreviewed
CVE-2001-1546
was published
Apr 30, 2022
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords ...
Moderate
Unreviewed
CVE-2002-1910
was published
Apr 30, 2022
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote...
Moderate
Unreviewed
CVE-2004-2172
was published
Apr 29, 2022
WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for...
Moderate
Unreviewed
CVE-2005-2281
was published
May 1, 2022
Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password...
Low
Unreviewed
CVE-2002-1975
was published
Apr 30, 2022
Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password"...
Low
Unreviewed
CVE-2002-1946
was published
Apr 30, 2022
libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5...
Moderate
Unreviewed
CVE-2008-3188
was published
May 1, 2022
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password...
Moderate
Unreviewed
CVE-2002-1872
was published
Apr 30, 2022
Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that...
Moderate
Unreviewed
CVE-2002-1697
was published
Apr 30, 2022
NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the...
Low
Unreviewed
CVE-2002-1682
was published
Apr 30, 2022
TYPO3 is vulnerable to insecure randomness during hash generation in forgot password function
Moderate
CVE-2010-3670
was published
for
typo3/cms-frontend
(Composer)
Apr 21, 2022
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000...
High
Unreviewed
CVE-2023-20185
was published
Jul 12, 2023
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net:...
High
Unreviewed
CVE-2021-32066
was published
May 24, 2022
Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a...
Moderate
Unreviewed
CVE-2023-26941
was published
Dec 5, 2023
Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a...
Moderate
Unreviewed
CVE-2023-26942
was published
Dec 5, 2023
Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a...
Moderate
Unreviewed
CVE-2023-26943
was published
Dec 5, 2023
Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions
High
CVE-2022-45379
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Nov 16, 2022
An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to...
Moderate
Unreviewed
CVE-2023-48034
was published
Nov 27, 2023
Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and...
Moderate
Unreviewed
CVE-2023-43757
was published
Nov 16, 2023
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send...
Moderate
Unreviewed
CVE-2023-47368
was published
Nov 9, 2023
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send...
Moderate
Unreviewed
CVE-2023-47366
was published
Nov 9, 2023
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers...
Moderate
Unreviewed
CVE-2023-47372
was published
Nov 9, 2023
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to...
Moderate
Unreviewed
CVE-2023-47367
was published
Nov 9, 2023
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send...
Moderate
Unreviewed
CVE-2023-47370
was published
Nov 9, 2023
ProTip!
Advisories are also available from the
GraphQL API