GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
235 advisories
Filter by severity
Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX,...
Moderate
Unreviewed
CVE-2025-3938
was published
May 22, 2025
IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that...
Moderate
Unreviewed
CVE-2024-55912
was published
May 2, 2025
HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit...
Moderate
Unreviewed
CVE-2024-30152
was published
Apr 25, 2025
An Improper Authorization vulnerability was identified in the EOL OVA based connect component...
Moderate
Unreviewed
CVE-2025-3838
was published
Apr 21, 2025
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected...
Moderate
Unreviewed
CVE-2024-22314
was published
Apr 16, 2025
IBM Aspera Console 3.4.0 through 3.4.4
uses weaker than expected cryptographic algorithms that...
Moderate
Unreviewed
CVE-2022-43851
was published
Apr 14, 2025
IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2024-31896
was published
Mar 25, 2025
Use of a Broken or Risky Cryptographic Algorithm, Use of Password Hash
With Insufficient...
Moderate
Unreviewed
CVE-2025-26486
was published
Mar 19, 2025
IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow...
Moderate
Unreviewed
CVE-2024-45643
was published
Mar 14, 2025
There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is...
Moderate
Unreviewed
CVE-2025-26708
was published
Mar 7, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client
uses...
Moderate
Unreviewed
CVE-2024-28780
was published
Feb 19, 2025
Brocade SANnav before SANnav 2.3.1b
enables weak TLS ciphers on ports 443 and 18082. In case of...
Moderate
Unreviewed
CVE-2024-10405
was published
Feb 15, 2025
IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the...
Moderate
Unreviewed
CVE-2024-49797
was published
Feb 6, 2025
Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky...
Moderate
Unreviewed
CVE-2024-37137
was published
Feb 3, 2025
In illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition...
Moderate
Unreviewed
CVE-2024-26317
was published
Jan 27, 2025
IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0...
Moderate
Unreviewed
CVE-2024-27256
was published
Jan 27, 2025
IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect...
Moderate
Unreviewed
CVE-2024-38320
was published
Jan 27, 2025
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than...
Moderate
Unreviewed
CVE-2024-22347
was published
Jan 20, 2025
IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a...
Moderate
Unreviewed
CVE-2024-51456
was published
Jan 12, 2025
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to...
Moderate
Unreviewed
CVE-2024-52366
was published
Jan 7, 2025
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected...
Moderate
Unreviewed
CVE-2024-41763
was published
Jan 4, 2025
Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic...
Moderate
Unreviewed
CVE-2024-28980
was published
Dec 13, 2024
Beego has Collision Hazards of MD5 in Cache Key Filenames
Moderate
CVE-2024-55885
was published
for
github.com/beego/beego
(Go)
Dec 12, 2024
IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that...
Moderate
Unreviewed
CVE-2024-41775
was published
Dec 3, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies
Moderate
CVE-2024-52801
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Dec 2, 2024
ProTip!
Advisories are also available from the
GraphQL API