GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,779
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,973
NuGet
715
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
18 advisories
Filter by severity
Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14...
Moderate
Unreviewed
CVE-2025-46632
was published
May 2, 2025
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup ...
Moderate
Unreviewed
CVE-2017-13086
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the...
Moderate
Unreviewed
CVE-2017-13081
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the...
Moderate
Unreviewed
CVE-2017-13079
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity...
Moderate
Unreviewed
CVE-2017-13088
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK)...
Moderate
Unreviewed
CVE-2017-13080
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL)...
Moderate
Unreviewed
CVE-2017-13084
was published
May 13, 2022
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK)...
Moderate
Unreviewed
CVE-2017-13078
was published
May 13, 2022
In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX...
Moderate
Unreviewed
CVE-2022-37660
was published
Feb 12, 2025
The authentication process to the web server uses a challenge response procedure which
inludes...
Moderate
Unreviewed
CVE-2024-11022
was published
Dec 6, 2024
PheonixAppAPI has visible Encoding Maps
Moderate
CVE-2024-41951
was published
for
PheonixAppAPI
(pip)
Jul 31, 2024
cocoon Reuses a Nonce, Key Pair in Encryption
Moderate
CVE-2024-21530
was published
for
cocoon
(Rust)
Oct 2, 2024
HashiCorp Vault Improper Input Validation vulnerability
Moderate
CVE-2023-4680
was published
for
github.com/hashicorp/vault
(Go)
Sep 15, 2023
The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless...
Moderate
Unreviewed
CVE-2023-7003
was published
Mar 15, 2024
Withdrawn: SFTPGo's JWT implmentation lacks certain security measures
Moderate
CVE-2024-40430
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Jul 22, 2024
•
withdrawn
Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App...
Moderate
Unreviewed
CVE-2024-36289
was published
Jun 17, 2024
Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session....
Moderate
Unreviewed
CVE-2024-23688
was published
Jan 20, 2024
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2...
Moderate
Unreviewed
CVE-2020-1759
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API