GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
256 advisories
Filter by severity
openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the...
High
Unreviewed
CVE-2026-81688
was published
Aug 27, 2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents,...
High
Unreviewed
CVE-2025-59325
was published
Aug 12, 2026
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent...
High
Unreviewed
CVE-2026-21079
was published
Aug 10, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS...
High
Unreviewed
CVE-2026-20157
was published
Jul 15, 2026
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
High
CVE-2026-54784
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
High
CVE-2026-34486
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 9, 2026
Antrea has Missing Encryption of Sensitive Data
High
CVE-2026-34992
was published
for
antrea.io/antrea
(Go)
Apr 3, 2026
A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with...
High
Unreviewed
CVE-2025-13453
was published
Jan 15, 2026
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS...
High
Unreviewed
CVE-2025-13053
was published
Dec 12, 2025
An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows...
High
Unreviewed
CVE-2025-48981
was published
Oct 8, 2025
Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to...
High
Unreviewed
CVE-2025-48862
was published
Aug 14, 2025
pyjwt v2.10.1 was discovered to contain weak encryption.
High
Unreviewed
CVE-2025-45768
was published
Jul 31, 2025
An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0.16.0. A...
High
Unreviewed
CVE-2025-32874
was published
Jul 16, 2025
git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes
was set, and the remote...
High
Unreviewed
CVE-2014-6274
was published
Jun 26, 2025
A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions),...
High
Unreviewed
CVE-2025-24008
was published
May 13, 2025
OpenDaylight SFC Insecure Shiro Cookie Configuration
High
CVE-2025-29314
was published
for
org.opendaylight.sfc:odl-sfc-openflow-renderer
(Maven)
Mar 24, 2025
A local user may find a configuration file on the client workstation with unencrypted sensitive...
High
Unreviewed
CVE-2024-23942
was published
Mar 18, 2025
Access control vulnerability in the identity authentication module
Impact: Successful...
High
Unreviewed
CVE-2024-56439
was published
Jan 8, 2025
Gradio uses insecure communication between the FRP client and server
High
CVE-2024-47871
was published
for
gradio
(pip)
Oct 10, 2024
Credentials to access device configuration were transmitted using an unencrypted protocol. These...
High
Unreviewed
CVE-2024-42495
was published
Sep 6, 2024
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain...
High
Unreviewed
CVE-2024-42657
was published
Aug 19, 2024
Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue...
High
Unreviewed
CVE-2024-7396
was published
Aug 5, 2024
NASA AIT-Core uses unencrypted channels to exchange data over the network
High
CVE-2024-35061
was published
for
ait-core
(pip)
May 21, 2024
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography...
High
Unreviewed
CVE-2024-0220
was published
Feb 22, 2024
Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what...
High
Unreviewed
CVE-2023-4537
was published
Feb 15, 2024
ProTip!
Advisories are also available from the
GraphQL API