GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
181 advisories
Filter by severity
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is...
High
Unreviewed
CVE-2021-23839
was published
May 24, 2022
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low...
High
Unreviewed
CVE-2019-9506
was published
May 24, 2022
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an...
High
Unreviewed
CVE-2023-26276
was published
Jun 27, 2023
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an...
High
Unreviewed
CVE-2023-30994
was published
Oct 14, 2023
IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could...
High
Unreviewed
CVE-2022-33160
was published
Oct 7, 2023
Vault Key Sealed With SHA1 PCRs
The measured boot solution implemented in EVE OS leans on...
High
Unreviewed
CVE-2023-43635
was published
Sep 20, 2023
IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic...
High
Unreviewed
CVE-2023-38730
was published
Aug 28, 2023
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration...
High
Unreviewed
CVE-2023-4331
was published
Aug 15, 2023
Broadcom RAID Controller web interface is vulnerable has an insecure default TLS configuration...
High
Unreviewed
CVE-2023-4326
was published
Aug 15, 2023
HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can...
High
Unreviewed
CVE-2023-23347
was published
Aug 9, 2023
HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can...
High
Unreviewed
CVE-2023-23346
was published
Aug 9, 2023
IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that...
High
Unreviewed
CVE-2021-38933
was published
Jul 19, 2023
there is a possible way to bypass cryptographic assurances due to a logic error in the code. This...
High
Unreviewed
CVE-2023-21399
was published
Jul 13, 2023
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM...
High
Unreviewed
CVE-2023-36749
was published
Jul 11, 2023
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered...
High
Unreviewed
CVE-2023-28006
was published
Jun 23, 2023
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type...
High
Unreviewed
CVE-2023-21115
was published
Jun 15, 2023
A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1...
High
Unreviewed
CVE-2022-43949
was published
Jun 13, 2023
CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm...
High
Unreviewed
CVE-2023-28076
was published
May 16, 2023
IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic...
High
Unreviewed
CVE-2022-22313
was published
May 6, 2023
A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2...
High
Unreviewed
CVE-2022-45858
was published
May 4, 2023
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11...
High
Unreviewed
CVE-2023-30441
was published
Apr 29, 2023
IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2...
High
Unreviewed
CVE-2023-27557
was published
Apr 28, 2023
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy...
High
Unreviewed
CVE-2020-7514
was published
May 24, 2022
The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the...
High
Unreviewed
CVE-2019-20138
was published
May 24, 2022
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in...
High
Unreviewed
CVE-2019-19962
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API