GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
462 advisories
Filter by severity
Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that...
Moderate
Unreviewed
CVE-2002-1697
was published
Apr 30, 2022
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password...
Moderate
Unreviewed
CVE-2002-1872
was published
Apr 30, 2022
libxcrypt in SUSE openSUSE 11.0 uses the DES algorithm when the configuration specifies the MD5...
Moderate
Unreviewed
CVE-2008-3188
was published
May 1, 2022
Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password"...
Low
Unreviewed
CVE-2002-1946
was published
Apr 30, 2022
Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password...
Low
Unreviewed
CVE-2002-1975
was published
Apr 30, 2022
WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for...
Moderate
Unreviewed
CVE-2005-2281
was published
May 1, 2022
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote...
Moderate
Unreviewed
CVE-2004-2172
was published
Apr 29, 2022
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords ...
Moderate
Unreviewed
CVE-2002-1910
was published
Apr 30, 2022
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users...
Moderate
Unreviewed
CVE-2001-1546
was published
Apr 30, 2022
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user...
Low
Unreviewed
CVE-2002-1739
was published
Apr 30, 2022
An issue in AIT-Deutschland Alpha Innotec Heatpumps wp2reg-V.3.88.0-9015 and Novelan Heatpumps...
Moderate
Unreviewed
CVE-2024-22894
was published
Jan 30, 2024
This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm ...
High
Unreviewed
CVE-2024-1224
was published
Mar 6, 2024
This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic...
High
Unreviewed
CVE-2024-25102
was published
Mar 6, 2024
Session data between cluster nodes during cluster synchronization is not properly encrypted in...
Critical
Unreviewed
CVE-2018-20810
was published
May 24, 2022
Lantronix XPort sends weakly encoded credentials within web request headers.
Moderate
Unreviewed
CVE-2023-7237
was published
Jan 24, 2024
IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that...
Moderate
Unreviewed
CVE-2022-32753
was published
Mar 22, 2024
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector...
High
Unreviewed
CVE-2020-11877
was published
May 24, 2022
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always...
Critical
Unreviewed
CVE-2011-4121
was published
Apr 22, 2022
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak...
High
Unreviewed
CVE-2012-2130
was published
Apr 23, 2022
IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that...
High
Unreviewed
CVE-2018-2007
was published
May 24, 2022
IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected...
High
Unreviewed
CVE-2018-1608
was published
May 24, 2022
The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the...
High
Unreviewed
CVE-2019-20138
was published
May 24, 2022
A missing secure communication definition and an incomplete TLS validation in the upgrade service...
Moderate
Unreviewed
CVE-2019-19101
was published
May 24, 2022
The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular...
Moderate
Unreviewed
CVE-2020-11735
was published
May 24, 2022
In versions 14.1.0-14.1.0.1 and 14.1.2.5-14.1.2.7, when a BIG-IP object is created or listed...
Moderate
Unreviewed
CVE-2020-5943
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API