GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
136 advisories
Filter by severity
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware...
Critical
Unreviewed
CVE-2018-10251
was published
May 13, 2022
Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the...
High
Unreviewed
CVE-2017-9137
was published
May 13, 2022
vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n...
Critical
Unreviewed
CVE-2017-8218
was published
May 13, 2022
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts,...
Critical
Unreviewed
CVE-2017-7964
was published
May 13, 2022
A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an...
High
Unreviewed
CVE-2017-6750
was published
May 13, 2022
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated,...
High
Unreviewed
CVE-2017-6692
was published
May 13, 2022
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an...
High
Unreviewed
CVE-2017-6689
was published
May 13, 2022
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote...
High
Unreviewed
CVE-2017-6688
was published
May 13, 2022
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated,...
High
Unreviewed
CVE-2017-6686
was published
May 13, 2022
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated,...
High
Unreviewed
CVE-2017-6687
was published
May 13, 2022
A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated,...
High
Unreviewed
CVE-2017-6685
was published
May 13, 2022
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote...
High
Unreviewed
CVE-2017-6684
was published
May 13, 2022
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting...
Moderate
Unreviewed
CVE-2017-5491
was published
May 13, 2022
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier....
High
Unreviewed
CVE-2017-5155
was published
May 13, 2022
A vulnerability has been identified in RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0...
High
Unreviewed
CVE-2017-12736
was published
May 13, 2022
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants...
Critical
Unreviewed
CVE-2017-12739
was published
May 13, 2022
A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic...
Critical
Unreviewed
CVE-2018-0130
was published
May 13, 2022
Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify...
High
Unreviewed
CVE-2018-10605
was published
May 13, 2022
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that...
High
Unreviewed
CVE-2018-1524
was published
May 13, 2022
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used...
Moderate
Unreviewed
CVE-2018-3825
was published
May 13, 2022
EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability...
Critical
Unreviewed
CVE-2017-8021
was published
May 13, 2022
Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change...
Critical
Unreviewed
CVE-2019-3909
was published
May 13, 2022
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings...
High
Unreviewed
CVE-2019-1994
was published
May 13, 2022
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a...
Critical
Unreviewed
CVE-2018-19275
was published
May 13, 2022
eVisitorPass contains default administrative credentials. An attacker could exploit this...
High
Unreviewed
CVE-2018-17497
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API