GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,041
Maven
5,000+
npm
3,733
NuGet
662
pip
3,414
Pub
12
RubyGems
891
Rust
866
Swift
36
Unreviewed advisories
All unreviewed
5,000+
249 advisories
Filter by severity
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover...
High
Unreviewed
CVE-2024-12432
was published
Dec 18, 2024
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature...
Moderate
Unreviewed
CVE-2024-20331
was published
Oct 23, 2024
An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate...
High
Unreviewed
CVE-2024-41708
was published
Sep 25, 2024
Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection...
Moderate
Unreviewed
CVE-2024-6348
was published
Aug 19, 2024
A vulnerability, which was classified as problematic, was found in projectsend up to r1605....
Moderate
Unreviewed
CVE-2024-7659
was published
Aug 12, 2024
Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow...
Moderate
Unreviewed
CVE-2024-42165
was published
Aug 12, 2024
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow...
Moderate
Unreviewed
CVE-2024-42164
was published
Aug 12, 2024
Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in...
High
Unreviewed
CVE-2024-21460
was published
Jul 1, 2024
iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th...
High
Unreviewed
CVE-2024-25943
was published
Jun 29, 2024
A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All...
High
Unreviewed
CVE-2024-35292
was published
Jun 11, 2024
ZendFramework Potential Information Disclosure and Insufficient Entropy vulnerabilities
High
GHSA-xg9w-r469-m455
was published
for
zendframework/zendframework
(Composer)
Jun 7, 2024
The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up...
Moderate
Unreviewed
CVE-2024-5149
was published
Jun 5, 2024
MileSight DeviceHub -
CWE-330 Use of Insufficiently Random Values may allow Authentication...
Critical
Unreviewed
CVE-2024-36389
was published
Jun 2, 2024
Use of Insufficiently Random Values vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3,...
Moderate
Unreviewed
CVE-2024-28013
was published
Mar 28, 2024
@nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys
Critical
GHSA-84c3-j8r2-mcm8
was published
for
@nfid/embed
(npm)
Feb 26, 2024
TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure...
Moderate
Unreviewed
CVE-2024-22473
was published
Feb 21, 2024
agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`
Critical
CVE-2024-1631
was published
for
@dfinity/auth-client
(npm)
Feb 21, 2024
Use of Insufficiently Random Values in github.com/greenpau/caddy-security
Moderate
CVE-2024-21495
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
High
Unreviewed
CVE-2024-0761
was published
Feb 6, 2024
Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session....
Moderate
Unreviewed
CVE-2024-23688
was published
Jan 20, 2024
Insecure random string generator used for sensitive data
High
CVE-2023-46740
was published
for
github.com/cubefs/cubefs
(Go)
Jan 3, 2024
In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This...
Moderate
Unreviewed
CVE-2023-32831
was published
Jan 2, 2024
A vulnerability classified as problematic has been found in Poly CCX 400, CCX 600, Trio 8800 and...
Low
Unreviewed
CVE-2023-4462
was published
Dec 29, 2023
Henschen & Associates court document management software does not sufficiently randomize file...
Moderate
Unreviewed
CVE-2023-6376
was published
Nov 30, 2023
PyPinkSign uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption
High
CVE-2023-48056
was published
for
pypinksign
(pip)
Nov 16, 2023
ProTip!
Advisories are also available from the
GraphQL API