GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,850
Maven
5,000+
npm
4,485
NuGet
779
pip
4,238
Pub
12
RubyGems
975
Rust
1,093
Swift
48
Unreviewed advisories
All unreviewed
5,000+
554 advisories
Filter by severity
Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability
in the Password class in...
High
Unreviewed
CVE-2025-58743
was published
Jan 21, 2026
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in the TLS/SSL server of Juniper...
High
Unreviewed
CVE-2026-21907
was published
Jan 15, 2026
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized...
Moderate
Unreviewed
CVE-2026-20833
was published
Jan 13, 2026
Jervis's AES CBC Mode is Without Authentication
High
CVE-2025-68931
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a SHA-256 Hex String Padding Bug
High
CVE-2025-68702
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis has Deterministic AES IV Derivation from Passphrase
High
CVE-2025-68701
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a RSA PKCS#1 Padding Vulnerability
High
CVE-2025-68698
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
jose-swift has JWT Signature Verification Bypass via None Algorithm
High
GHSA-88q6-jcjg-hvmw
was published
for
github.com/beatt83/jose-swift
(Swift)
Jan 9, 2026
A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak...
Moderate
Unreviewed
CVE-2025-14175
was published
Dec 29, 2025
A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL...
Moderate
Unreviewed
CVE-2021-47712
was published
Dec 18, 2025
AWS SDK for PHP's S3 Encryption Client has a Key Commitment Issue
Moderate
CVE-2025-14761
was published
for
aws/aws-sdk-php
(Composer)
Dec 18, 2025
AWS SDK for Ruby's S3 Encryption Client has a Key Commitment Issue
Moderate
CVE-2025-14762
was published
for
aws-sdk-s3
(RubyGems)
Dec 18, 2025
Amazon S3 Encryption Client has a Key Commitment Issue
Moderate
CVE-2025-14764
was published
for
github.com/aws/amazon-s3-encryption-client-go/v3
(Go)
Dec 18, 2025
Amazon S3 Encryption Client for Java has a Key Commitment Issue
Moderate
CVE-2025-14763
was published
for
software.amazon.encryption.s3:amazon-s3-encryption-client-java
(Maven)
Dec 18, 2025
Amazon S3 Encryption Client for .NET has a Key Commitment Issue
Moderate
CVE-2025-14759
was published
for
Amazon.Extensions.S3.Encryption
(NuGet)
Dec 18, 2025
A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function...
Moderate
Unreviewed
CVE-2025-14636
was published
Dec 13, 2025
Apache StreamPark uses a Weak Encryption Algorithm
High
CVE-2025-54981
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker...
High
Unreviewed
CVE-2025-65831
was published
Dec 10, 2025
Altcha Proof-of-Work obfuscation mode cryptanalytic break
Moderate
CVE-2025-65849
was published
for
altcha
(npm)
Dec 8, 2025
libcrux incorrectly calculates on aarch64
High
GHSA-2cgv-28vr-rv6j
was published
for
libcrux-intrinsics
(Rust)
Dec 4, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
CVE-2025-66017
was published
for
cggmp21
(Rust)
Nov 25, 2025
IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could...
Moderate
Unreviewed
CVE-2025-36150
was published
Nov 24, 2025
IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information,...
Moderate
Unreviewed
CVE-2025-36161
was published
Nov 20, 2025
The vulnerability, if exploited, could allow a miscreant with read
access to Edge Project files...
High
Unreviewed
CVE-2025-9317
was published
Nov 15, 2025
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11...
Moderate
Unreviewed
CVE-2025-54340
was published
Nov 14, 2025
ProTip!
Advisories are also available from the
GraphQL API