GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,829
Erlang
36
GitHub Actions
33
Go
2,446
Maven
5,000+
npm
4,065
NuGet
723
pip
3,866
Pub
12
RubyGems
943
Rust
1,009
Swift
39
Unreviewed advisories
All unreviewed
5,000+
265 advisories
Filter by severity
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000...
High
Unreviewed
CVE-2023-20185
was published
Jul 12, 2023
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow...
Moderate
Unreviewed
CVE-2022-43485
was published
Jul 6, 2023
Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of...
High
Unreviewed
CVE-2023-1385
was published
Jul 6, 2023
Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S,...
Moderate
Unreviewed
CVE-2022-26080
was published
Jul 6, 2023
Use of insufficiently random values vulnerability in User Management Functionality in Synology...
High
Unreviewed
CVE-2023-2729
was published
Jun 13, 2023
Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker...
High
Unreviewed
CVE-2023-1898
was published
Jun 12, 2023
crypto-js uses insecure random numbers
Moderate
CVE-2020-36732
was published
for
crypto-js
(npm)
Jun 12, 2023
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random...
Critical
Unreviewed
CVE-2023-2884
was published
May 25, 2023
A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This...
Low
Unreviewed
CVE-2023-2418
was published
Apr 29, 2023
Duplicate Advisory: Lemur subject to insecure random generation
High
GHSA-r4xg-4wrv-w72h
was published
for
lemur
(pip)
Apr 19, 2023
•
withdrawn
The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers...
High
Unreviewed
CVE-2023-26855
was published
Apr 4, 2023
Akuvox E11 contains a function that encrypts messages which are then forwarded. The IV vector and...
High
Unreviewed
CVE-2023-0343
was published
Mar 31, 2023
This vulnerability allows network-adjacent attackers to bypass authentication on affected...
High
Unreviewed
CVE-2022-43636
was published
Mar 29, 2023
Lemur subject to insecure random generation
High
CVE-2023-30797
was published
for
lemur
(pip)
Mar 1, 2023
A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the...
Moderate
Unreviewed
CVE-2023-20016
was published
Feb 23, 2023
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP...
Critical
Unreviewed
CVE-2022-43501
was published
Feb 10, 2023
Rancher cattle-token is predictable
High
CVE-2022-43755
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39...
Moderate
Unreviewed
CVE-2023-22912
was published
Jan 20, 2023
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017...
High
Unreviewed
CVE-2017-5242
was published
Jan 13, 2023
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version...
High
Unreviewed
CVE-2023-22601
was published
Jan 13, 2023
A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key...
Moderate
Unreviewed
CVE-2021-26407
was published
Jan 11, 2023
A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic. Affected by...
High
Unreviewed
CVE-2019-25089
was published
Dec 27, 2022
A vulnerability, which was classified as problematic, has been found in fredsmith utils. This...
Moderate
Unreviewed
CVE-2021-4277
was published
Dec 25, 2022
DNS NuGet package uses insufficiently random values
Critical
CVE-2021-4248
was published
for
DNS
(NuGet)
Dec 18, 2022
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE...
Critical
Unreviewed
CVE-2022-46353
was published
Dec 13, 2022
ProTip!
Advisories are also available from the
GraphQL API