GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,544
Erlang
33
GitHub Actions
25
Go
2,220
Maven
5,000+
npm
3,890
NuGet
700
pip
3,657
Pub
12
RubyGems
913
Rust
942
Swift
38
Unreviewed advisories
All unreviewed
5,000+
487 advisories
Filter by severity
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit...
Moderate
Unreviewed
CVE-2007-6755
was published
May 1, 2022
Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum...
Moderate
Unreviewed
CVE-2021-36647
was published
Jan 17, 2023
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead...
Moderate
Unreviewed
CVE-2005-2946
was published
May 1, 2022
IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a...
Moderate
Unreviewed
CVE-2024-51456
was published
Jan 12, 2025
A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This...
Low
Unreviewed
CVE-2025-2920
was published
Mar 28, 2025
IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2024-31896
was published
Mar 25, 2025
The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
High
Unreviewed
CVE-2025-2539
was published
Mar 20, 2025
Use of a Broken or Risky Cryptographic Algorithm, Use of Password Hash
With Insufficient...
Moderate
Unreviewed
CVE-2025-26486
was published
Mar 19, 2025
IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow...
Moderate
Unreviewed
CVE-2024-45643
was published
Mar 14, 2025
There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is...
Moderate
Unreviewed
CVE-2025-26708
was published
Mar 7, 2025
Emissary May Use a Broken or Risky Cryptographic Algorithm
High
CVE-2025-27508
was published
for
gov.nsa.emissary:emissary
(Maven)
Mar 5, 2025
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application...
High
Unreviewed
CVE-2024-48847
was published
Dec 5, 2024
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
High
CVE-2015-0226
was published
for
org.apache.ws.security:wss4j
(Maven)
May 14, 2022
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client
uses...
Moderate
Unreviewed
CVE-2024-28780
was published
Feb 19, 2025
python-jose algorithm confusion with OpenSSH ECDSA keys
Critical
CVE-2024-33663
was published
for
python-jose
(pip)
Apr 26, 2024
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5...
High
Unreviewed
CVE-2023-28509
was published
Mar 29, 2023
Brocade SANnav before SANnav 2.3.1b
enables weak TLS ciphers on ports 443 and 18082. In case of...
Moderate
Unreviewed
CVE-2024-10405
was published
Feb 15, 2025
Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
High
Unreviewed
CVE-2024-4282
was published
Feb 15, 2025
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Moderate
CVE-2022-23540
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W...
High
Unreviewed
CVE-2025-22936
was published
Feb 6, 2025
Unauthenticated crypto and weak IV in Magento\Framework\Encryption
High
CVE-2016-6485
was published
for
magento/community-edition
(Composer)
Nov 20, 2019
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501...
High
Unreviewed
CVE-2024-52884
was published
Feb 7, 2025
Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of...
Low
Unreviewed
CVE-2025-22475
was published
Feb 4, 2025
IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the...
Moderate
Unreviewed
CVE-2024-49797
was published
Feb 6, 2025
Brocade SANnav before Brocade SANnav 2.2.2 supports key exchange algorithms, which are considered...
High
Unreviewed
CVE-2022-43934
was published
Feb 4, 2025
ProTip!
Advisories are also available from the
GraphQL API