GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
462 advisories
Filter by severity
In Modem, there is a possible information disclosure due to incorrect error handling. This could...
High
Unreviewed
CVE-2025-20667
was published
May 5, 2025
Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management...
High
Unreviewed
CVE-2025-46626
was published
May 2, 2025
Apache Wicket insecure defaults
High
CVE-2014-7808
was published
for
org.apache.wicket:wicket-core
(Maven)
May 13, 2022
An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no...
High
Unreviewed
CVE-2017-17436
was published
May 14, 2022
A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix...
Critical
Unreviewed
CVE-2017-7903
was published
May 17, 2022
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750...
Critical
Unreviewed
CVE-2017-7905
was published
May 13, 2022
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch...
Moderate
Unreviewed
CVE-2017-5160
was published
May 13, 2022
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is...
Critical
Unreviewed
CVE-2017-8076
was published
May 17, 2022
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow...
High
Unreviewed
CVE-2016-2379
was published
May 17, 2022
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the...
Moderate
Unreviewed
CVE-2016-6225
was published
May 14, 2022
hitek.jar in Hitek Software's Automize uses weak encryption when encrypting SSH/SFTP and...
High
Unreviewed
CVE-2016-10102
was published
May 17, 2022
Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the...
Moderate
Unreviewed
CVE-2016-10104
was published
May 17, 2022
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may...
High
Unreviewed
CVE-2020-14481
was published
Feb 25, 2022
HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities....
Low
Unreviewed
CVE-2024-42177
was published
Apr 17, 2025
When viewing an email message A, which contains an attached message B, where B is encrypted or...
Moderate
Unreviewed
CVE-2022-1520
was published
Dec 22, 2022
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to...
Moderate
Unreviewed
CVE-2005-4900
was published
May 1, 2022
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict...
High
Unreviewed
CVE-2014-0224
was published
May 13, 2022
Certain General Electric Renewable Energy products have inadequate encryption strength. This...
Critical
Unreviewed
CVE-2022-24116
was published
Dec 26, 2022
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier...
High
Unreviewed
CVE-2013-4508
was published
May 13, 2022
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet...
Moderate
Unreviewed
CVE-2011-3389
was published
May 13, 2022
The use of a weak cryptographic key pair in the signature verification process in WPS Office ...
Critical
Unreviewed
CVE-2025-2516
was published
Mar 27, 2025
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could...
Moderate
Unreviewed
CVE-2022-43922
was published
Feb 1, 2023
In the ownCloud application before 2.15 for Android, the lock protection mechanism can be...
Moderate
Unreviewed
CVE-2020-36250
was published
May 24, 2022
Driver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a...
High
Unreviewed
CVE-2022-43460
was published
Feb 13, 2023
A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as...
Low
Unreviewed
CVE-2025-2349
was published
Mar 17, 2025
ProTip!
Advisories are also available from the
GraphQL API