GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
462 advisories
Filter by severity
Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows...
High
Unreviewed
CVE-2017-14797
was published
May 17, 2022
Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600...
High
Unreviewed
CVE-2017-8174
was published
May 17, 2022
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows...
High
Unreviewed
CVE-2017-1271
was published
May 17, 2022
An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no...
High
Unreviewed
CVE-2017-17436
was published
May 14, 2022
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to...
Critical
Unreviewed
CVE-2017-14090
was published
May 14, 2022
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2017-1664
was published
May 14, 2022
In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android,...
High
Unreviewed
CVE-2018-5298
was published
May 14, 2022
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2018-1425
was published
May 14, 2022
IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for...
Moderate
Unreviewed
CVE-2015-4953
was published
May 14, 2022
IBM Team Concert (RTC) 5.0, 5.0.1, 5.0.2, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, and 6.0.5 stores...
High
Unreviewed
CVE-2017-1701
was published
May 14, 2022
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker...
High
Unreviewed
CVE-2017-1473
was published
May 14, 2022
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 uses weaker than expected...
High
Unreviewed
CVE-2017-1255
was published
May 14, 2022
IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash...
Moderate
Unreviewed
CVE-2014-0841
was published
May 14, 2022
Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version ...
Critical
Unreviewed
CVE-2018-15124
was published
May 14, 2022
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10...
High
Unreviewed
CVE-2016-4693
was published
May 14, 2022
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the...
Moderate
Unreviewed
CVE-2016-6225
was published
May 14, 2022
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption...
High
Unreviewed
CVE-2017-13699
was published
May 14, 2022
Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum,...
Critical
Unreviewed
CVE-2018-7242
was published
May 14, 2022
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow...
High
Unreviewed
CVE-2018-1648
was published
May 14, 2022
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining...
High
Unreviewed
CVE-2013-7469
was published
May 14, 2022
Using remote content in encrypted messages can lead to the disclosure of plaintext. This...
High
Unreviewed
CVE-2018-5184
was published
May 14, 2022
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2017-1665
was published
May 14, 2022
comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL...
Moderate
Unreviewed
CVE-2018-6653
was published
May 13, 2022
System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with...
High
Unreviewed
CVE-2018-6635
was published
May 13, 2022
Weak Cryptography in PHP-Proxy
High
CVE-2018-19784
was published
for
athlon1600/php-proxy
(Composer)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API