GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
158 advisories
Filter by severity
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is...
Moderate
Unreviewed
CVE-2017-7150
was published
May 13, 2022
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not...
Critical
Unreviewed
CVE-2017-1601
was published
May 13, 2022
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can...
Critical
Unreviewed
CVE-2017-14189
was published
May 13, 2022
IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant...
Moderate
Unreviewed
CVE-2017-1386
was published
May 13, 2022
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting...
Critical
Unreviewed
CVE-2017-12861
was published
May 13, 2022
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have...
Critical
Unreviewed
CVE-2017-1221
was published
May 13, 2022
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong...
Critical
Unreviewed
CVE-2017-1196
was published
May 13, 2022
A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and...
Critical
Unreviewed
CVE-2017-16727
was published
May 13, 2022
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity...
High
Unreviewed
CVE-2017-1597
was published
May 13, 2022
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow...
High
Unreviewed
CVE-2018-0204
was published
May 13, 2022
Open Dental before version 18.4 installs a mysql database and uses the default credentials of ...
Critical
Unreviewed
CVE-2018-15719
was published
May 13, 2022
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization...
High
Unreviewed
CVE-2018-1101
was published
May 13, 2022
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks...
Moderate
Unreviewed
CVE-2018-5389
was published
May 13, 2022
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank...
Critical
Unreviewed
CVE-2019-9123
was published
May 13, 2022
A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port...
High
Unreviewed
CVE-2019-7676
was published
May 13, 2022
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to...
Critical
Unreviewed
CVE-2019-7674
was published
May 13, 2022
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by...
High
Unreviewed
CVE-2018-1956
was published
May 13, 2022
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users...
High
Unreviewed
CVE-2018-1680
was published
May 13, 2022
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise...
High
Unreviewed
CVE-2018-15766
was published
May 13, 2022
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T...
High
Unreviewed
CVE-2018-6312
was published
May 13, 2022
RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived...
High
Unreviewed
CVE-2012-2441
was published
May 13, 2022
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long...
High
Unreviewed
CVE-2022-29700
was published
Apr 28, 2022
gpw generates shorter passwords than required
High
Unreviewed
CVE-2011-4931
was published
Apr 22, 2022
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access...
Critical
Unreviewed
CVE-2022-1039
was published
Apr 21, 2022
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
Moderate
Unreviewed
CVE-2022-1236
was published
Apr 6, 2022
ProTip!
Advisories are also available from the
GraphQL API