GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
433 advisories
Filter by severity
magic-crypt uses insecure cryptographic algorithms
Low
GHSA-gmx7-gr5q-85w5
was published
for
magic-crypt
(Rust)
Dec 30, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app...
High
Unreviewed
CVE-2023-32414
was published
Jun 23, 2023
Moodle uses the same key for QR login and auto-login
Moderate
CVE-2024-38277
was published
for
moodle/moodle
(Composer)
Jun 18, 2024
Portainer improperly uses an encryption algorithm in the AesEncrypt function
High
CVE-2024-33662
was published
for
github.com/portainer/portainer
(Go)
Oct 2, 2024
Apache Answer: Predictable Authorization Token Using UUIDv1
Low
CVE-2024-45719
was published
for
github.com/apache/incubator-answer
(Go)
Nov 22, 2024
An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it...
Moderate
Unreviewed
CVE-2023-37301
was published
Jun 30, 2023
A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software...
High
Unreviewed
CVE-2020-3549
was published
May 24, 2022
rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks
High
CVE-2022-3273
was published
for
rdiffweb
(pip)
Oct 6, 2022
Apache Tomcat - XSS in generated JSPs
Moderate
CVE-2024-52318
was published
for
org.apache.tomcat:tomcat-jasper
(Maven)
Nov 18, 2024
Apache Tomcat Request and/or response mix-up
Moderate
CVE-2024-52317
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Nov 18, 2024
In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying...
Moderate
Unreviewed
CVE-2023-20942
was published
Jul 13, 2023
Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows...
Low
Unreviewed
CVE-2023-6728
was published
Oct 17, 2024
Snowflake JDBC Security Advisory
Moderate
CVE-2024-43382
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Oct 30, 2024
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800,...
Moderate
Unreviewed
CVE-2024-45259
was published
Oct 24, 2024
Inadequate Encryption Strength in python-keystoneclient
Critical
CVE-2013-2166
was published
for
python-keystoneclient
(pip)
Oct 12, 2021
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases,...
Moderate
Unreviewed
CVE-2013-2566
was published
May 13, 2022
Pycrypto generates weak key parameters
High
CVE-2018-6594
was published
for
pycrypto
(pip)
Jul 12, 2018
Apache Linkis Authentication Bypass vulnerability
Critical
CVE-2023-27987
was published
for
org.apache.linkis:linkis
(Maven)
Jul 6, 2023
An unauthenticated local attacker can decrypt the devices config file and therefore compromise...
High
Unreviewed
CVE-2024-45273
was published
Oct 15, 2024
Dozzle uses unsafe hash for passwords
Low
CVE-2024-47182
was published
for
github.com/amir20/dozzle
(Go)
Oct 9, 2024
An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive...
High
Unreviewed
CVE-2024-41594
was published
Oct 3, 2024
The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain...
High
Unreviewed
CVE-2024-8455
was published
Sep 30, 2024
OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.
High
Unreviewed
CVE-2024-22892
was published
Sep 25, 2024
ProTip!
Advisories are also available from the
GraphQL API