GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,270
Erlang
31
GitHub Actions
21
Go
2,044
Maven
5,000+
npm
3,736
NuGet
663
pip
3,414
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
214 advisories
Filter by severity
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM...
Moderate
Unreviewed
CVE-2018-10846
was published
May 13, 2022
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen...
Moderate
Unreviewed
CVE-2018-10845
was published
May 13, 2022
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health...
Moderate
Unreviewed
CVE-2023-0296
was published
Jan 17, 2023
Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum...
Moderate
Unreviewed
CVE-2021-36647
was published
Jan 17, 2023
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic...
Moderate
Unreviewed
CVE-2019-4156
was published
May 24, 2022
A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker...
Moderate
Unreviewed
CVE-2021-43774
was published
Mar 4, 2022
An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol...
Moderate
Unreviewed
CVE-2021-45081
was published
Feb 21, 2022
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in...
Moderate
Unreviewed
CVE-2021-43550
was published
Dec 28, 2021
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel...
Moderate
Unreviewed
CVE-2018-0735
was published
May 13, 2022
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel...
Moderate
Unreviewed
CVE-2018-0734
was published
May 13, 2022
FusionSphere OpenStack V100R006C00SPC102(NFV)has a week cryptographic algorithm vulnerability....
Moderate
Unreviewed
CVE-2017-8191
was published
May 14, 2022
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small...
Moderate
Unreviewed
CVE-2017-8866
was published
May 14, 2022
Huawei DP300 V500R002C00; TP3206 V100R002C00; ViewPoint 9030 V100R011C02; V100R011C03 have a use...
Moderate
Unreviewed
CVE-2017-17167
was published
May 14, 2022
DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability....
Moderate
Unreviewed
CVE-2017-15326
was published
May 14, 2022
The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security...
Moderate
Unreviewed
CVE-2017-14937
was published
May 14, 2022
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.
Moderate
Unreviewed
CVE-2018-18587
was published
May 14, 2022
WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such...
Moderate
Unreviewed
CVE-2018-5152
was published
May 13, 2022
There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker...
Moderate
Unreviewed
CVE-2018-7959
was published
May 13, 2022
Usage of SSLv2 and SSLv3 leads to transmitted data decryption in Kraftway 24F2XG Router firmware...
Moderate
Unreviewed
CVE-2018-15355
was published
May 13, 2022
A Pektron Passive Keyless Entry and Start (PKES) system, as used on the Tesla Model S and...
Moderate
Unreviewed
CVE-2018-16806
was published
May 13, 2022
OceanStor 5800 V3 with software V300R002C00 and V300R002C10, OceanStor 6900 V3 V300R001C00 has an...
Moderate
Unreviewed
CVE-2017-8157
was published
May 13, 2022
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67...
Moderate
Unreviewed
CVE-2017-17382
was published
May 13, 2022
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption...
Moderate
Unreviewed
CVE-2017-1339
was published
May 13, 2022
A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and...
Moderate
Unreviewed
CVE-2017-10668
was published
May 13, 2022
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation...
Moderate
Unreviewed
CVE-2017-16718
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API