GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
57 advisories
Filter by severity
Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not...
High
Unreviewed
CVE-2025-1828
was published
Mar 11, 2025
Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy...
High
Unreviewed
CVE-2025-1860
was published
Mar 28, 2025
Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces...
High
Unreviewed
CVE-2025-40920
was published
Aug 11, 2025
Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely.
The...
High
Unreviewed
CVE-2025-40923
was published
Jul 16, 2025
Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF...
High
Unreviewed
CVE-2025-40915
was published
Jun 11, 2025
The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient...
High
Unreviewed
CVE-2024-7315
was published
Oct 2, 2024
An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs...
High
Unreviewed
CVE-2017-17845
was published
May 14, 2022
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time...
High
Unreviewed
CVE-2016-10180
was published
May 13, 2022
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not...
High
Unreviewed
CVE-2017-5493
was published
May 13, 2022
The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces...
High
Unreviewed
CVE-2009-3238
was published
May 2, 2022
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random...
High
Unreviewed
CVE-2008-0166
was published
May 1, 2022
A use of a cryptographically weak pseudo-random number generator vulnerability in the...
High
Unreviewed
CVE-2021-26091
was published
Mar 24, 2025
A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including...
High
Unreviewed
CVE-2025-1796
was published
Mar 20, 2025
The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand()...
High
Unreviewed
CVE-2018-25107
was published
Dec 29, 2024
Passeo uses insecure random number generator
High
CVE-2022-23472
was published
for
Passeo
(pip)
Dec 6, 2022
The goTenna Pro series does not use SecureRandom when generating its cryptographic keys. The...
High
Unreviewed
CVE-2024-47126
was published
Sep 26, 2024
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
High
CVE-2019-11842
was published
for
matrix-sydent
(pip)
May 24, 2022
The goTenna Pro ATAK Plugin does not use SecureRandom when generating
its cryptographic keys....
High
Unreviewed
CVE-2024-45723
was published
Sep 26, 2024
Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to...
High
Unreviewed
CVE-2021-34600
was published
Jan 21, 2022
Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.
High
Unreviewed
CVE-2024-34538
was published
May 6, 2024
RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed ...
High
Unreviewed
CVE-2024-25389
was published
Mar 27, 2024
An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate...
High
Unreviewed
CVE-2023-27791
was published
Oct 19, 2023
The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using...
High
Unreviewed
CVE-2022-26943
was published
Oct 19, 2023
The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6...
High
Unreviewed
CVE-2023-39910
was published
Aug 9, 2023
Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator.
High
Unreviewed
CVE-2023-32549
was published
Jun 6, 2023
ProTip!
Advisories are also available from the
GraphQL API