GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
103 advisories
Filter by severity
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 ...
Moderate
Unreviewed
CVE-2022-24041
was published
May 11, 2022
Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with...
High
Unreviewed
CVE-2019-3907
was published
May 13, 2022
Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing...
High
Unreviewed
CVE-2019-0030
was published
May 13, 2022
global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations...
High
Unreviewed
CVE-2019-7649
was published
May 13, 2022
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker...
Critical
Unreviewed
CVE-2019-6563
was published
May 13, 2022
Improper rate limiting in Koel
High
CVE-2021-33563
was published
for
phanan/koel
(Composer)
Jun 1, 2021
Improper privilege management in Keycloak
High
CVE-2020-14389
was published
for
org.keycloak:keycloak-core
(Maven)
Nov 10, 2021
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password...
Critical
Unreviewed
CVE-2018-10618
was published
May 13, 2022
Password recovery exploitation vulnerability in the non-certificate-based authentication...
Critical
Unreviewed
CVE-2017-3962
was published
May 13, 2022
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for...
Moderate
Unreviewed
CVE-2017-11131
was published
May 13, 2022
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and...
High
Unreviewed
CVE-2018-1447
was published
May 13, 2022
An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users...
Critical
Unreviewed
CVE-2018-15680
was published
May 13, 2022
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%...
High
Unreviewed
CVE-2018-9233
was published
May 13, 2022
Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password...
Moderate
Unreviewed
CVE-2022-0022
was published
Mar 10, 2022
A use of password hash with insufficient computational effort vulnerability [CWE-916] in...
High
Unreviewed
CVE-2022-26115
was published
Feb 16, 2023
Password Shucking Vulnerability
Moderate
CVE-2023-27580
was published
for
codeigniter4/shield
(Composer)
Mar 13, 2023
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered...
Moderate
Unreviewed
CVE-2021-38314
was published
May 24, 2022
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker...
High
Unreviewed
CVE-2021-43989
was published
Dec 24, 2021
Use of Password Hash With Insufficient Computational Effort in Apache Derby
Moderate
CVE-2009-4269
was published
for
org.apache.derby:derby
(Maven)
May 2, 2022
The application was vulnerable to an authenticated information disclosure, allowing...
Moderate
Unreviewed
CVE-2022-40295
was published
Nov 1, 2022
crypto-es PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
Critical
CVE-2023-46133
was published
for
crypto-es
(npm)
Oct 25, 2023
Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers...
High
Unreviewed
CVE-2023-5846
was published
Nov 2, 2023
A vulnerability classified as problematic was found in Supcon InPlant SCADA up to 20230901....
Low
Unreviewed
CVE-2023-4986
was published
Sep 15, 2023
Buttercup allows attackers to obtain the hash of the master password
Moderate
CVE-2023-41646
was published
for
buttercup
(npm)
Sep 8, 2023
The Priva TopControl Suite contains predictable credentials for the SSH service, based on the...
High
Unreviewed
CVE-2022-3010
was published
Jan 2, 2024
ProTip!
Advisories are also available from the
GraphQL API