GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
66 advisories
Filter by severity
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context...
Moderate
Unreviewed
CVE-2004-2761
was published
Apr 29, 2022
OpenStack Glance Signature Verification Bypass
Moderate
CVE-2015-8234
was published
for
glance
(pip)
May 17, 2022
Rack Gem Subject to Denial of Service via Hash Collisions
Moderate
CVE-2011-5036
was published
for
org.jruby:jruby-parent
(RubyGems)
May 17, 2022
Mattermost Server uses weak hashing for OAuth, email verification tokens and invitations
High
CVE-2017-18917
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform ...
High
Unreviewed
CVE-2019-13539
was published
May 24, 2022
Reversible One-Way Hash in io.github.javaezlib:JavaEZ
High
CVE-2022-29249
was published
for
io.github.javaezlib:JavaEZ
(Maven)
May 25, 2022
WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An...
Moderate
Unreviewed
CVE-2022-29835
was published
Sep 20, 2022
The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse...
Moderate
Unreviewed
CVE-2022-3433
was published
Oct 11, 2022
Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions
High
CVE-2022-45379
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Nov 16, 2022
All versions of Econolite EOS traffic control software are vulnerable to CWE-328: Use of Weak...
Moderate
Unreviewed
CVE-2023-0452
was published
Jan 26, 2023
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could...
Moderate
Unreviewed
CVE-2022-43922
was published
Feb 1, 2023
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by...
Critical
Unreviewed
CVE-2022-45141
was published
Mar 7, 2023
A vulnerability was found in NFine Rapid Development Platform 20230511. It has been classified as...
Low
Unreviewed
CVE-2023-2900
was published
May 25, 2023
Duplicate Advisory: EVE Seals Vault Key With SHA1 PCRs
High
GHSA-h929-fvvp-882c
was published
for
github.com/lf-edge/eve
(Go)
Sep 20, 2023
•
withdrawn
Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 Fronts
High
GHSA-5jvg-8j6f-vpmc
was published
for
github.com/lf-edge/eve
(Go)
Sep 20, 2023
•
withdrawn
crypto-es PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
Critical
CVE-2023-46133
was published
for
crypto-es
(npm)
Oct 25, 2023
crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
Critical
CVE-2023-46233
was published
for
crypto-js
(npm)
Oct 25, 2023
A vulnerability has been identified in SCALANCE XB205-3 (SC, PN) (All versions < V4.5), SCALANCE...
Moderate
Unreviewed
CVE-2023-44319
was published
Nov 14, 2023
A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware...
Moderate
Unreviewed
CVE-2023-5962
was published
Dec 23, 2023
Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can...
Moderate
Unreviewed
CVE-2024-1040
was published
Feb 2, 2024
An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to...
Moderate
Unreviewed
CVE-2024-32211
was published
May 1, 2024
Beego privilege escalation vulnerability
High
CVE-2024-40465
was published
for
github.com/beego/beego/v2
(Go)
Jul 31, 2024
Certain switch models from PLANET Technology use an insecure hashing function to hash user...
Moderate
Unreviewed
CVE-2024-8453
was published
Sep 30, 2024
Dozzle uses unsafe hash for passwords
Low
CVE-2024-47182
was published
for
github.com/amir20/dozzle
(Go)
Oct 9, 2024
ProTip!
Advisories are also available from the
GraphQL API