GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
467 advisories
Filter by severity
VersionVault Express exposes sensitive information that an attacker can use to impersonate the...
Critical
Unreviewed
CVE-2021-27779
was published
May 26, 2022
ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the...
High
Unreviewed
CVE-2021-41302
was published
May 24, 2022
An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones...
High
Unreviewed
CVE-2021-22932
was published
May 24, 2022
A vulnerability has been identified in Climatix POL909 (AWM module) (All versions < V11.34). The...
High
Unreviewed
CVE-2021-40366
was published
May 24, 2022
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open...
Moderate
Unreviewed
CVE-2021-3774
was published
May 24, 2022
The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions....
Moderate
Unreviewed
CVE-2021-35236
was published
May 24, 2022
On systems running Arista EOS and CloudEOS with the affected release version, when using shared...
Moderate
Unreviewed
CVE-2021-28496
was published
May 24, 2022
LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client...
Moderate
Unreviewed
CVE-2021-3882
was published
May 24, 2022
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
Moderate
Unreviewed
CVE-2020-12730
was published
May 24, 2022
Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all...
Moderate
Unreviewed
CVE-2021-22782
was published
May 24, 2022
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0...
High
Unreviewed
CVE-2021-26100
was published
May 24, 2022
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a...
High
Unreviewed
CVE-2021-34825
was published
May 24, 2022
IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information...
Moderate
Unreviewed
CVE-2021-20567
was published
May 24, 2022
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre...
Moderate
Unreviewed
CVE-2021-23211
was published
May 24, 2022
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information,...
Moderate
Unreviewed
CVE-2019-4471
was published
May 24, 2022
homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and...
High
Unreviewed
CVE-2020-24396
was published
May 24, 2022
IBM API Connect V10 is impacted by insecure communications during database replication. As the...
High
Unreviewed
CVE-2020-4695
was published
May 24, 2022
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance...
Moderate
Unreviewed
CVE-2020-29024
was published
May 24, 2022
Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices...
High
Unreviewed
CVE-2020-23162
was published
May 24, 2022
Skyworth GN542VF Boa version 0.94.13 does not set the Secure flag for the session cookie in an...
High
Unreviewed
CVE-2020-26732
was published
May 24, 2022
IBM Security Guardium Insights 2.0.2 does not set the secure attribute on authorization tokens or...
Moderate
Unreviewed
CVE-2020-4597
was published
May 24, 2022
The encryption function of NHIServiSignAdapter fail to verify the file path input by users....
High
Unreviewed
CVE-2020-25842
was published
May 24, 2022
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
Moderate
Unreviewed
CVE-2020-35658
was published
May 24, 2022
** DISPUTED ** In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled....
High
Unreviewed
CVE-2020-35587
was published
May 24, 2022
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and...
High
Unreviewed
CVE-2020-14254
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API