GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,825
Erlang
36
GitHub Actions
32
Go
2,417
Maven
5,000+
npm
4,054
NuGet
723
pip
3,845
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
265 advisories
Filter by severity
A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569...
High
Unreviewed
CVE-2017-17704
was published
May 13, 2022
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be...
High
Unreviewed
CVE-2017-17091
was published
May 13, 2022
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10...
Critical
Unreviewed
CVE-2017-16924
was published
May 13, 2022
Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380...
High
Unreviewed
CVE-2017-15654
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity...
Moderate
Unreviewed
CVE-2017-13088
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the...
High
Unreviewed
CVE-2017-13082
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL)...
Moderate
Unreviewed
CVE-2017-13084
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup ...
Moderate
Unreviewed
CVE-2017-13086
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the...
Moderate
Unreviewed
CVE-2017-13081
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group...
Moderate
Unreviewed
CVE-2017-13087
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK)...
Moderate
Unreviewed
CVE-2017-13077
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the...
Moderate
Unreviewed
CVE-2017-13079
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK)...
Moderate
Unreviewed
CVE-2017-13078
was published
May 13, 2022
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with...
High
Unreviewed
CVE-2017-0897
was published
May 13, 2022
A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to...
Moderate
Unreviewed
CVE-2017-12361
was published
May 13, 2022
A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen...
Critical
Unreviewed
CVE-2017-7902
was published
May 13, 2022
Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology...
Moderate
Unreviewed
CVE-2018-13280
was published
May 13, 2022
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that...
Critical
Unreviewed
CVE-2018-17888
was published
May 13, 2022
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared...
Moderate
Unreviewed
CVE-2018-1279
was published
May 13, 2022
The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well...
Critical
Unreviewed
CVE-2019-0007
was published
May 13, 2022
The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary...
Critical
Unreviewed
CVE-2018-18602
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK)...
Moderate
Unreviewed
CVE-2017-13080
was published
May 13, 2022
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's...
Moderate
Unreviewed
CVE-2018-1108
was published
May 13, 2022
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time...
High
Unreviewed
CVE-2016-10180
was published
May 13, 2022
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
Critical
Unreviewed
CVE-2019-9898
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API