GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
46 advisories
Filter by severity
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step"...
Moderate
Unreviewed
CVE-2026-25250
was published
Aug 27, 2026
Multiple
TP-Link Kasa smart home devices contain insufficient cryptographic protections
in the...
High
Unreviewed
CVE-2026-76784
was published
Aug 26, 2026
A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and...
High
Unreviewed
CVE-2022-20742
was published
May 4, 2022
Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a...
Critical
Unreviewed
CVE-2026-17666
was published
Jul 30, 2026
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in...
High
Unreviewed
CVE-2026-59776
was published
Jul 21, 2026
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a...
Moderate
Unreviewed
CVE-2026-58638
was published
Jul 14, 2026
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform...
High
Unreviewed
CVE-2026-55144
was published
Jul 14, 2026
OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
Moderate
CVE-2026-48480
was published
for
io.netty.incubator:netty-incubator-codec-ohttp
(Maven)
Jun 23, 2026
An improper implementation of TLS certificate validation vulnerability found in ReadyCloud client...
Moderate
Unreviewed
CVE-2026-0420
was published
Jun 9, 2026
Deno: Miller-Rabin Primality Test Allows Zero Rounds
High
CVE-2026-49440
was published
for
deno
(Rust)
Jun 16, 2026
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux...
High
Unreviewed
CVE-2026-9266
was published
Jun 12, 2026
Issue summary: When an application drives an AES-OCB context through the
public EVP_Cipher() one...
High
Unreviewed
CVE-2026-45445
was published
Jun 9, 2026
Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)
peer key, the peer...
Low
Unreviewed
CVE-2026-42770
was published
Jun 9, 2026
Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV
(RFC 8452) mishandle the...
Moderate
Unreviewed
CVE-2026-45446
was published
Jun 9, 2026
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware...
Moderate
Unreviewed
CVE-2025-69418
was published
Jan 27, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted...
Moderate
Unreviewed
CVE-2026-29142
was published
Apr 2, 2026
jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction
High
CVE-2026-4601
was published
for
jsrsasign
(npm)
Mar 23, 2026
sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey
High
CVE-2026-4258
was published
for
sjcl
(npm)
Mar 17, 2026
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High...
Moderate
Unreviewed
CVE-2018-5383
was published
May 13, 2022
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
High
Unreviewed
CVE-2025-47383
was published
Mar 2, 2026
Deno node:crypto doesn't finalize cipher
Critical
CVE-2026-22863
was published
for
deno
(Rust)
Jan 16, 2026
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks...
High
Unreviewed
CVE-2021-33560
was published
May 24, 2022
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2025-60704
was published
Nov 11, 2025
frost-core: refresh shares with smaller min_signers will reduce security of group
Moderate
CVE-2025-58359
was published
for
frost-core
(Rust)
Sep 3, 2025
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash...
Moderate
Unreviewed
CVE-2025-49600
was published
Jul 4, 2025
ProTip!
Advisories are also available from the
GraphQL API