GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,360
Erlang
33
GitHub Actions
22
Go
2,127
Maven
5,000+
npm
3,793
NuGet
683
pip
3,471
Pub
12
RubyGems
894
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
194 advisories
Filter by severity
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the...
Moderate
Unreviewed
CVE-2022-34826
was published
Jul 16, 2022
All versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric PLCs and XG5000 PLC programming...
Moderate
Unreviewed
CVE-2022-2758
was published
Sep 1, 2022
Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a Violation of Secure...
Moderate
Unreviewed
CVE-2022-30683
was published
Sep 17, 2022
WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An...
Moderate
Unreviewed
CVE-2022-29835
was published
Sep 20, 2022
In affected versions of Octopus Server it was identified that the same encryption process was...
Moderate
Unreviewed
CVE-2022-2781
was published
Oct 6, 2022
An entity in Network Configuration Manager product is misconfigured and exposing password field...
Moderate
Unreviewed
CVE-2021-35226
was published
Oct 11, 2022
The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse...
Moderate
Unreviewed
CVE-2022-3433
was published
Oct 11, 2022
SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method...
Moderate
Unreviewed
CVE-2022-41209
was published
Oct 12, 2022
The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named ...
Moderate
Unreviewed
CVE-2022-3206
was published
Oct 17, 2022
The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up...
Moderate
Unreviewed
CVE-2022-4036
was published
Nov 29, 2022
When viewing an email message A, which contains an attached message B, where B is encrypted or...
Moderate
Unreviewed
CVE-2022-1520
was published
Dec 22, 2022
AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
Moderate
CVE-2022-2582
was published
for
github.com/aws/aws-sdk-go
(Go)
Dec 28, 2022
DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt...
Moderate
Unreviewed
CVE-2021-40341
was published
Jan 6, 2023
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A...
Moderate
Unreviewed
CVE-2022-34445
was published
Feb 11, 2023
SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version...
Moderate
Unreviewed
CVE-2022-34385
was published
Feb 11, 2023
Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for...
Moderate
Unreviewed
CVE-2023-22271
was published
Mar 22, 2023
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE...
Moderate
Unreviewed
CVE-2023-29054
was published
Apr 11, 2023
Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier)...
Moderate
Unreviewed
CVE-2023-28124
was published
Apr 19, 2023
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool...
Moderate
Unreviewed
CVE-2023-1764
was published
May 17, 2023
Dgraph Audit Log Encryption Vulnerability
Moderate
CVE-2023-31135
was published
for
github.com/dgraph-io/dgraph
(Go)
May 17, 2023
Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can...
Moderate
Unreviewed
CVE-2023-33982
was published
May 24, 2023
A compromised web child process could disable web security opening restrictions, leading to a new...
Moderate
Unreviewed
CVE-2023-23597
was published
Jun 2, 2023
Under certain circumstances, a call to the <code>bind</code> function may have resulted in the...
Moderate
Unreviewed
CVE-2023-29549
was published
Jun 2, 2023
Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains...
Moderate
Unreviewed
CVE-2023-33283
was published
Jun 7, 2023
An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it...
Moderate
Unreviewed
CVE-2023-37301
was published
Jun 30, 2023
ProTip!
Advisories are also available from the
GraphQL API