GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            468 advisories
        Filter by severity
        
      
      
    
                    
                      Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12478
                      
                      was published
                      Oct 29, 2025 
                    
                  
                    
                      Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55248
                      
                      was published
                        for
                        
                          Microsoft.NetCore.App.Runtime.linux-arm
                        
                        (NuGet)
                      Oct 15, 2025 
                    
                  
                    
                      Apache Spark has Inadequate Encryption Strength
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55039
                      
                      was published
                        for
                        
                          org.apache.spark:spark-network-common_2.12
                        
                        (Maven)
                      Oct 15, 2025 
                    
                  
                    
                      Duplicate Advisory: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
                    
                      
  Moderate
                    
                
                      
                        GHSA-987x-96fq-9384
                      
                      was published
                        for
                        
                          Microsoft.NetCore.App.Runtime.linux-arm
                        
                        (NuGet)
                      Oct 14, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-46409
                      
                      was published
                      Aug 28, 2025 
                    
                  
                    
                      ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-45765
                      
                      was published
                      Aug 7, 2025 
                    
                  
                    
                      jsrsasign v11.1.0 was discovered to contain weak encryption.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-45764
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      jwt v5.4.3 was discovered to contain weak encryption.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-45770
                      
                      was published
                      Jul 31, 2025 
                    
                  
                    
                      php-jwt v6.11.0 was discovered to contain weak encryption.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-45769
                      
                      was published
                      Jul 31, 2025 
                    
                  
                    
                      IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-36106
                      
                      was published
                      Jul 21, 2025 
                    
                  
                    
                      A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-7789
                      
                      was published
                      Jul 18, 2025 
                    
                  
                    
                      Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-7398
                      
                      was published
                      Jul 18, 2025 
                    
                  
                    
                      Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-48823
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      Weak server key used for TLS encryption. The following products are affected: Acronis Cyber...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-48960
                      
                      was published
                      Jun 4, 2025 
                    
                  
                    
                      An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43925
                      
                      was published
                      Jun 3, 2025 
                    
                  
                    
                      IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-38341
                      
                      was published
                      May 28, 2025 
                    
                  
                    
                      A vulnerability classified as problematic was found in calmkart Django-sso-server up to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-4894
                      
                      was published
                      May 18, 2025 
                    
                  
                    
                      Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-27524
                      
                      was published
                      May 15, 2025 
                    
                  
                    
                      Inadequate encryption strength for some Edge Orchestrator software for Intel(R) Tiber™ Edge...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-22446
                      
                      was published
                      May 13, 2025 
                    
                  
                    
                      In Modem, there is a possible information disclosure due to incorrect error handling. This could...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20667
                      
                      was published
                      May 5, 2025 
                    
                  
                    
                      Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-46626
                      
                      was published
                      May 2, 2025 
                    
                  
                    
                      HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities....
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-42177
                      
                      was published
                      Apr 17, 2025 
                    
                  
                    
                      The use of a weak cryptographic key pair in the signature verification process in WPS Office ...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2516
                      
                      was published
                      Mar 27, 2025 
                    
                  
                    
                      A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2349
                      
                      was published
                      Mar 17, 2025 
                    
                  
                    
                      A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-54089
                      
                      was published
                      Feb 11, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API