GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
266 advisories
Filter by severity
golang.org/x/crypto/salsa20/salsa uses insufficiently random values
Moderate
CVE-2019-11840
was published
for
golang.org/x/crypto
(Go)
May 24, 2022
gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which...
Moderate
Unreviewed
CVE-2019-11690
was published
May 24, 2022
Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including...
High
Unreviewed
CVE-2019-11641
was published
May 24, 2022
Insecure PRNG use in random_password_generator
High
CVE-2019-25061
was published
for
random_password_generator
(RubyGems)
May 19, 2022
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp...
Critical
Unreviewed
CVE-2014-6311
was published
May 17, 2022
The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy...
Moderate
Unreviewed
CVE-2008-5162
was published
May 17, 2022
Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it...
Moderate
Unreviewed
CVE-2008-4905
was published
May 17, 2022
MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded...
Moderate
Unreviewed
CVE-2008-4929
was published
May 17, 2022
Fat Free CRM has fixed token value
Moderate
CVE-2013-7222
was published
for
fat_free_crm
(RubyGems)
May 17, 2022
SimpleGeo python-oauth2 vulnerable to the use of Insufficiently Random Values to generate nonces
Moderate
CVE-2013-4347
was published
for
oauth2
(pip)
May 17, 2022
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which...
High
Unreviewed
CVE-2016-5085
was published
May 17, 2022
Froxlor guessable password reset token
Critical
CVE-2016-5100
was published
for
froxlor/froxlor
(Composer)
May 17, 2022
In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random...
Moderate
Unreviewed
CVE-2015-9019
was published
May 17, 2022
A Predictable Value Range from Previous Values issue was discovered in Rockwell Automation Allen...
High
Unreviewed
CVE-2017-7901
was published
May 17, 2022
PWR-Q200 does not use random values for source ports of DNS query packets, which allows remote...
High
Unreviewed
CVE-2017-10874
was published
May 17, 2022
Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide...
High
Unreviewed
CVE-2022-30782
was published
May 17, 2022
Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to...
Moderate
Unreviewed
CVE-2018-11045
was published
May 14, 2022
Ansible uses a socket with predictable filename in /tmp
Low
CVE-2013-4259
was published
for
Ansible
(pip)
May 14, 2022
The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum...
High
Unreviewed
CVE-2018-17987
was published
May 14, 2022
In random_get_bytes of random.c, there is a possible degradation of randomness due to an insecure...
High
Unreviewed
CVE-2019-1997
was published
May 14, 2022
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
High
Unreviewed
CVE-2018-20025
was published
May 14, 2022
An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares...
Moderate
Unreviewed
CVE-2018-19983
was published
May 13, 2022
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data ...
Critical
Unreviewed
CVE-2018-18375
was published
May 13, 2022
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies,...
Critical
Unreviewed
CVE-2018-16239
was published
May 13, 2022
POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be...
High
Unreviewed
CVE-2018-15807
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API