GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
35 advisories
Filter by severity
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an...
High
Unreviewed
CVE-2026-41879
was published
Jul 10, 2026
The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords,...
Moderate
Unreviewed
CVE-2026-10540
was published
Jul 1, 2026
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to...
Moderate
Unreviewed
CVE-2026-13455
was published
Jun 30, 2026
Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because...
Moderate
Unreviewed
CVE-2026-53692
was published
Jun 30, 2026
GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password,...
Critical
Unreviewed
CVE-2026-36182
was published
Jun 4, 2026
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context...
Moderate
Unreviewed
CVE-2004-2761
was published
Apr 29, 2022
Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows...
Critical
Unreviewed
CVE-2020-37168
was published
May 13, 2026
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4...
Moderate
Unreviewed
CVE-2025-3576
was published
Apr 15, 2025
A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric...
Moderate
Unreviewed
CVE-2026-21717
was published
Mar 30, 2026
An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi...
Moderate
Unreviewed
CVE-2025-41762
was published
Mar 9, 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5...
Moderate
Unreviewed
CVE-2026-27754
was published
Feb 27, 2026
The devices are vulnerable to an authentication bypass due to flaws in the authorization...
Critical
Unreviewed
CVE-2025-41652
was published
May 27, 2025
Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can...
Moderate
Unreviewed
CVE-2024-1040
was published
Feb 2, 2024
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote...
Moderate
Unreviewed
CVE-2024-10026
was published
Jan 30, 2025
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak...
Moderate
Unreviewed
CVE-2025-54535
was published
Jul 28, 2025
Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e...
High
Unreviewed
CVE-2025-41256
was published
Jun 26, 2025
The application uses a weak password hash function, allowing an attacker to crack the weak...
Moderate
Unreviewed
CVE-2025-49197
was published
Jun 12, 2025
IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6...
Moderate
Unreviewed
CVE-2024-38341
was published
May 28, 2025
Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data...
Moderate
Unreviewed
CVE-2024-23589
was published
May 30, 2025
The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up...
Low
Unreviewed
CVE-2025-48931
was published
May 28, 2025
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform ...
High
Unreviewed
CVE-2019-13539
was published
May 24, 2022
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could...
Moderate
Unreviewed
CVE-2022-43922
was published
Feb 1, 2023
The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password...
Critical
Unreviewed
CVE-2025-27595
was published
Mar 14, 2025
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application...
High
Unreviewed
CVE-2024-48847
was published
Dec 5, 2024
ProTip!
Advisories are also available from the
GraphQL API