GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,270
Erlang
31
GitHub Actions
21
Go
2,044
Maven
5,000+
npm
3,736
NuGet
663
pip
3,414
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
432 advisories
Filter by severity
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble...
Moderate
Unreviewed
CVE-2021-3789
was published
May 24, 2022
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the...
Low
Unreviewed
CVE-2020-14263
was published
May 24, 2022
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have inadequate encryption...
High
Unreviewed
CVE-2021-38464
was published
May 24, 2022
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could...
High
Unreviewed
CVE-2021-38862
was published
May 24, 2022
IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected...
High
Unreviewed
CVE-2021-38925
was published
May 24, 2022
The user and password data base is exposed by an unprotected web server resource. Passwords are...
High
Unreviewed
CVE-2021-23855
was published
May 24, 2022
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number...
High
Unreviewed
CVE-2021-41829
was published
May 24, 2022
In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component...
Moderate
Unreviewed
CVE-2021-41061
was published
May 24, 2022
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may...
High
Unreviewed
CVE-2021-31796
was published
May 24, 2022
The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is...
Moderate
Unreviewed
CVE-2021-31797
was published
May 24, 2022
The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1...
Moderate
Unreviewed
CVE-2021-31798
was published
May 24, 2022
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such...
Moderate
Unreviewed
CVE-2021-39272
was published
May 24, 2022
In SapphireIMS 4097_1, the password in the database is stored in Base64 format.
High
Unreviewed
CVE-2017-16632
was published
May 24, 2022
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted...
Moderate
Unreviewed
CVE-2021-37546
was published
May 24, 2022
In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment...
Moderate
Unreviewed
CVE-2021-37540
was published
May 24, 2022
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
Moderate
Unreviewed
CVE-2021-37551
was published
May 24, 2022
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net:...
High
Unreviewed
CVE-2021-32066
was published
May 24, 2022
In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data.
Moderate
Unreviewed
CVE-2021-37588
was published
May 24, 2022
In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data.
Moderate
Unreviewed
CVE-2021-37587
was published
May 24, 2022
IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected...
High
Unreviewed
CVE-2021-20337
was published
May 24, 2022
A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS,...
Moderate
Unreviewed
CVE-2021-36769
was published
May 24, 2022
IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could...
High
Unreviewed
CVE-2021-20360
was published
May 24, 2022
IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could...
Moderate
Unreviewed
CVE-2021-20369
was published
May 24, 2022
IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which...
High
Unreviewed
CVE-2021-29794
was published
May 24, 2022
A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4...
Critical
Unreviewed
CVE-2021-24020
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API