GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,783
Erlang
36
GitHub Actions
29
Go
2,353
Maven
5,000+
npm
3,977
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
451 advisories
Filter by severity
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is...
Critical
Unreviewed
CVE-2017-8076
was published
May 17, 2022
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.
High
Unreviewed
CVE-2016-5056
was published
May 17, 2022
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow...
High
Unreviewed
CVE-2016-2379
was published
May 17, 2022
Due to a lack of standard encryption when transmitting sensitive information over the internet to...
High
Unreviewed
CVE-2017-5239
was published
May 17, 2022
Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the...
Moderate
Unreviewed
CVE-2016-10104
was published
May 17, 2022
hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and...
High
Unreviewed
CVE-2016-10102
was published
May 17, 2022
An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently...
High
Unreviewed
CVE-2017-5999
was published
May 17, 2022
IBM QRadar 7.2 uses outdated hashing algorithms to hash certain passwords, which could allow a...
High
Unreviewed
CVE-2016-2879
was published
May 17, 2022
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue...
Moderate
Unreviewed
CVE-2016-4685
was published
May 17, 2022
IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information,...
Moderate
Unreviewed
CVE-2016-3034
was published
May 17, 2022
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software...
Moderate
Unreviewed
CVE-2015-8085
was published
May 17, 2022
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software...
Moderate
Unreviewed
CVE-2015-8086
was published
May 17, 2022
Jenkins Subversion Plugin Stores Credentials with Base64 Encoding
Moderate
CVE-2013-6372
was published
for
org.jenkins-ci.plugins:subversion
(Maven)
May 17, 2022
Python Keyring does not securely initialize encryption cipher
High
CVE-2012-4571
was published
for
keyring
(pip)
May 17, 2022
Beaker Sensitive Information Disclosure vulnerability
Moderate
CVE-2012-3458
was published
for
beaker
(pip)
May 17, 2022
Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through...
Moderate
Unreviewed
CVE-2020-16235
was published
May 20, 2022
Use of a Broken or Risky Cryptographic Algorithm in XWiki Crypto API
Moderate
CVE-2022-29161
was published
for
org.xwiki.platform:xwiki-platform-crypto
(Maven)
May 24, 2022
IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that...
High
Unreviewed
CVE-2018-2007
was published
May 24, 2022
IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected...
High
Unreviewed
CVE-2018-1608
was published
May 24, 2022
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2019-4151
was published
May 24, 2022
Session data between cluster nodes during cluster synchronization is not properly encrypted in...
Critical
Unreviewed
CVE-2018-20810
was published
May 24, 2022
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses...
Moderate
Unreviewed
CVE-2019-4102
was published
May 24, 2022
In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values...
Moderate
Unreviewed
CVE-2019-10638
was published
May 24, 2022
The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure ...
High
Unreviewed
CVE-2019-10639
was published
May 24, 2022
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is...
High
Unreviewed
CVE-2019-14332
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API