GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
32 advisories
Filter by severity
Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy,...
Moderate
Unreviewed
CVE-2024-56370
was published
Apr 5, 2025
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt...
Moderate
Unreviewed
CVE-2025-27551
was published
Mar 26, 2025
Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of...
Moderate
Unreviewed
CVE-2024-58036
was published
Apr 7, 2025
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt...
Moderate
Unreviewed
CVE-2025-27552
was published
Mar 26, 2025
WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of...
Moderate
Unreviewed
CVE-2024-52322
was published
Apr 7, 2025
Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy,...
Moderate
Unreviewed
CVE-2024-57868
was published
Apr 7, 2025
A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon...
Moderate
Unreviewed
CVE-2017-6030
was published
May 13, 2022
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying...
Moderate
Unreviewed
CVE-2016-2564
was published
May 13, 2022
The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they...
Moderate
Unreviewed
CVE-2024-9055
was published
Mar 17, 2025
TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure...
Moderate
Unreviewed
CVE-2024-22473
was published
Feb 21, 2024
In RsaKeyPairGenerator::getNumberOfIterations of RSAKeyPairGenerator.java, an incorrect...
Moderate
Unreviewed
CVE-2018-9426
was published
Dec 3, 2024
Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG...
Moderate
Unreviewed
CVE-2024-26329
was published
Apr 5, 2024
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature...
Moderate
Unreviewed
CVE-2024-20331
was published
Oct 23, 2024
An insufficient entropy vulnerability caused by the improper use of a randomness function with...
Moderate
Unreviewed
CVE-2024-38270
was published
Sep 10, 2024
An issue was discovered in Samsung Mobile Processor, Automotive Processor, Wearable Processor,...
Moderate
Unreviewed
CVE-2023-49927
was published
Jun 5, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An...
Moderate
Unreviewed
CVE-2022-27221
was published
Jun 15, 2022
An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If...
Moderate
Unreviewed
CVE-2023-34973
was published
Aug 24, 2023
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated,...
Moderate
Unreviewed
CVE-2023-38357
was published
Aug 1, 2023
?The affected TBox RTUs generate software security tokens using insufficient entropy. The random...
Moderate
Unreviewed
CVE-2023-36610
was published
Jul 3, 2023
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC)...
Moderate
Unreviewed
CVE-2022-20941
was published
Nov 16, 2022
It's possible that an authenticated user guess other session IDs based on its own. Also it's...
Moderate
Unreviewed
CVE-2020-1773
was published
May 24, 2022
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local...
Moderate
Unreviewed
CVE-2016-2858
was published
May 13, 2022
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys...
Moderate
Unreviewed
CVE-2017-2625
was published
May 13, 2022
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local...
Moderate
Unreviewed
CVE-2017-2626
was published
May 14, 2022
A security feature bypass vulnerability exists when Windows Hyper-V BIOS loader fails to provide...
Moderate
Unreviewed
CVE-2018-8435
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API