GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
452 advisories
Filter by severity
Dell PowerScale OneFS, versions 9.2.0.x through 9.4.0.x contain an information vulnerability. A...
High
Unreviewed
CVE-2022-34444
was published
Feb 11, 2023
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker...
Moderate
Unreviewed
CVE-2022-35720
was published
Feb 8, 2023
IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker...
High
Unreviewed
CVE-2022-22462
was published
Jan 26, 2023
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected...
High
Unreviewed
CVE-2022-43917
was published
Jan 26, 2023
All versions of Econolite EOS traffic control software are vulnerable to CWE-328: Use of Weak...
Moderate
Unreviewed
CVE-2023-0452
was published
Jan 26, 2023
Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum...
Moderate
Unreviewed
CVE-2021-36647
was published
Jan 17, 2023
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health...
Moderate
Unreviewed
CVE-2023-0296
was published
Jan 17, 2023
Collision of hash values in github.com/bnb-chain/tss-lib
Critical
CVE-2022-47931
was published
for
github.com/bnb-chain/tss-lib
(Go)
Dec 23, 2022
IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic...
High
Unreviewed
CVE-2022-22461
was published
Dec 22, 2022
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Moderate
CVE-2022-23540
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
jsonwebtoken unrestricted key type could lead to legacy keys usage
High
CVE-2022-23539
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing...
Moderate
Unreviewed
CVE-2022-20513
was published
Dec 20, 2022
IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an...
High
Unreviewed
CVE-2022-38391
was published
Dec 20, 2022
A vulnerability, which was classified as problematic, has been found in Click Studios...
Moderate
Unreviewed
CVE-2022-4610
was published
Dec 19, 2022
Use of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a...
Moderate
Unreviewed
CVE-2022-46832
was published
Dec 13, 2022
Use of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a...
Moderate
Unreviewed
CVE-2022-46833
was published
Dec 13, 2022
Use of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a...
Moderate
Unreviewed
CVE-2022-46834
was published
Dec 13, 2022
Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an...
Moderate
Unreviewed
CVE-2022-46140
was published
Dec 13, 2022
Use of a Broken or Risky Cryptographic Algorithm in SICK RFU61x firmware version <v2.25 allows a...
Moderate
Unreviewed
CVE-2022-27581
was published
Dec 13, 2022
IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could...
High
Unreviewed
CVE-2022-34361
was published
Dec 6, 2022
IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker...
High
Unreviewed
CVE-2022-34320
was published
Nov 15, 2022
IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker...
High
Unreviewed
CVE-2022-34319
was published
Nov 14, 2022
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation...
Moderate
Unreviewed
CVE-2022-45195
was published
Nov 13, 2022
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database...
High
Unreviewed
CVE-2021-27784
was published
Nov 1, 2022
SIF's Digital Signature Hash Algorithms Not Validated
Moderate
CVE-2022-39237
was published
for
github.com/sylabs/sif/v2
(Go)
Oct 6, 2022
ProTip!
Advisories are also available from the
GraphQL API