GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
40 advisories
Filter by severity
Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery
Critical
CVE-2026-44523
was published
for
github.com/enchant97/note-mark/backend
(Go)
May 7, 2026
fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
Critical
CVE-2026-44351
was published
for
fast-jwt
(npm)
May 6, 2026
ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain...
Critical
Unreviewed
CVE-2018-25272
was published
Apr 22, 2026
Session data between cluster nodes during cluster synchronization is not properly encrypted in...
Critical
Unreviewed
CVE-2018-20810
was published
May 24, 2022
Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19...
Critical
Unreviewed
CVE-2025-12478
was published
Oct 29, 2025
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2...
Critical
Unreviewed
CVE-2017-11317
was published
May 13, 2022
ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective...
Critical
Unreviewed
CVE-2025-45765
was published
Aug 7, 2025
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a...
Critical
Unreviewed
CVE-2021-42949
was published
Sep 17, 2022
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750...
Critical
Unreviewed
CVE-2017-7905
was published
May 13, 2022
A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix...
Critical
Unreviewed
CVE-2017-7903
was published
May 17, 2022
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is...
Critical
Unreviewed
CVE-2017-8076
was published
May 17, 2022
Certain General Electric Renewable Energy products have inadequate encryption strength. This...
Critical
Unreviewed
CVE-2022-24116
was published
Dec 26, 2022
The use of a weak cryptographic key pair in the signature verification process in WPS Office ...
Critical
Unreviewed
CVE-2025-2516
was published
Mar 27, 2025
Inadequate Encryption Strength
Critical
CVE-2017-1000486
was published
for
org.primefaces:primefaces
(Maven)
Jun 3, 2021
Inadequate Encryption Strength in python-keystoneclient
Critical
CVE-2013-2166
was published
for
python-keystoneclient
(pip)
Oct 12, 2021
Apache Linkis Authentication Bypass vulnerability
Critical
CVE-2023-27987
was published
for
org.apache.linkis:linkis
(Maven)
Jul 6, 2023
Under certain circumstances the communication between exacqVision Client and exacqVision Server...
Critical
Unreviewed
CVE-2024-32758
was published
Aug 2, 2024
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always...
Critical
Unreviewed
CVE-2011-4121
was published
Apr 22, 2022
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by...
Critical
Unreviewed
CVE-2022-45141
was published
Mar 7, 2023
Certain NETGEAR devices are affected by weak cryptography. This affects D7000v2 before 1.0.0.62,...
Critical
Unreviewed
CVE-2021-45512
was published
Dec 27, 2021
Dolibarr ERP and CRM Insecure Encryption
Critical
CVE-2017-7888
was published
for
dolibarr/dolibarr
(Composer)
May 17, 2022
Elliptic Curve Key Disclosure in go-jose
Critical
CVE-2016-9121
was published
for
github.com/square/go-jose
(Go)
Jun 23, 2021
In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure...
Critical
Unreviewed
CVE-2015-0575
was published
May 17, 2022
In all Qualcomm products with Android releases from CAF using the Linux kernel, a rollback...
Critical
Unreviewed
CVE-2014-9975
was published
May 17, 2022
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to...
Critical
Unreviewed
CVE-2017-14090
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API