GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,170
Erlang
30
GitHub Actions
19
Go
1,981
Maven
5,000+
npm
3,700
NuGet
656
pip
3,319
Pub
11
RubyGems
882
Rust
834
Swift
35
Unreviewed advisories
All unreviewed
5,000+
445 advisories
Filter by severity
golang.org/x/crypto/ssh Denial of service via crafted Signer
High
CVE-2022-27191
was published
for
golang.org/x/crypto
(Go)
Mar 19, 2022
Logic error in Matrix SDK for Android
Moderate
CVE-2021-40824
was published
for
org.matrix.android:matrix-android-sdk2
(Maven)
May 24, 2022
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2....
Critical
Unreviewed
CVE-2021-31556
was published
May 24, 2022
The combination of various cryptographic issues in the session management of FortiMail 6.4.0...
High
Unreviewed
CVE-2021-26095
was published
May 24, 2022
Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0...
Moderate
Unreviewed
CVE-2021-26099
was published
May 24, 2022
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a...
Moderate
Unreviewed
CVE-2021-23993
was published
May 24, 2022
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS...
Moderate
Unreviewed
CVE-2021-32591
was published
Dec 9, 2021
A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual...
High
Unreviewed
CVE-2019-1706
was published
May 24, 2022
The fingerprint module has a security risk of brute force cracking. Successful exploitation of...
Moderate
Unreviewed
CVE-2021-40006
was published
Jan 11, 2022
matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver
Moderate
CVE-2021-40823
was published
for
matrix-js-sdk
(npm)
Sep 14, 2021
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to...
High
Unreviewed
CVE-2021-46559
was published
Jan 27, 2022
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than...
Moderate
Unreviewed
CVE-2022-22310
was published
Jan 20, 2022
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic...
High
Unreviewed
CVE-2021-45487
was published
Dec 26, 2021
In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.
High
Unreviewed
CVE-2021-45488
was published
Dec 26, 2021
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
Critical
Unreviewed
CVE-2021-42216
was published
Dec 16, 2021
Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query...
Moderate
Unreviewed
CVE-2021-37606
was published
May 24, 2022
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
Moderate
Unreviewed
CVE-2021-25761
was published
May 24, 2022
Nablarch Incomplete Cryptography
Critical
CVE-2019-5919
was published
for
com.nablarch.framework:nablarch-fw-web
(Maven)
May 13, 2022
WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An...
Moderate
Unreviewed
CVE-2022-29835
was published
Sep 20, 2022
LTI 1.3 Tool Library's function used to generate random nonces not sufficiently cryptographically complex before v5.0
High
CVE-2022-31157
was published
for
packbackbooks/lti-1-3-php-library
(Composer)
Jul 15, 2022
A vulnerability in the automatic decryption process in Cisco Umbrella Secure Web Gateway (SWG)...
Moderate
Unreviewed
CVE-2022-20805
was published
Apr 22, 2022
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C...
Moderate
Unreviewed
CVE-2022-21800
was published
Feb 19, 2022
Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar...
Moderate
Unreviewed
CVE-2022-0377
was published
Mar 1, 2022
Reversible One-Way Hash in io.github.javaezlib:JavaEZ
High
CVE-2022-29249
was published
for
io.github.javaezlib:JavaEZ
(Maven)
May 25, 2022
ProTip!
Advisories are also available from the
GraphQL API