GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,231
Erlang
31
GitHub Actions
20
Go
1,991
Maven
5,000+
npm
3,709
NuGet
661
pip
3,341
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
166 advisories
Filter by severity
A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic....
Moderate
Unreviewed
CVE-2024-3735
was published
Apr 13, 2024
Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password...
Moderate
Unreviewed
CVE-2024-51398
was published
Nov 1, 2024
D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password,...
Moderate
Unreviewed
CVE-2024-48272
was published
Oct 30, 2024
D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for...
High
Unreviewed
CVE-2024-48271
was published
Oct 30, 2024
HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network...
Moderate
Unreviewed
CVE-2024-21865
was published
Mar 25, 2024
rdiffweb vulnerable to password complexity bypass leading to weak passwords
Moderate
CVE-2022-3326
was published
for
rdiffweb
(pip)
Sep 30, 2022
rdiffweb contains Weak Password Requirements
High
CVE-2022-3179
was published
for
rdiffweb
(pip)
Sep 14, 2022
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute...
High
Unreviewed
CVE-2024-7293
was published
Oct 9, 2024
In the goTenna Pro ATAK Plugin application, the encryption keys are
stored along with a static...
Moderate
Unreviewed
CVE-2024-45374
was published
Sep 26, 2024
The goTenna Pro series uses a weak password for the QR broadcast message. If the QR broadcast...
Moderate
Unreviewed
CVE-2024-47121
was published
Sep 26, 2024
Modoboa has Weak Password Requirements
Moderate
CVE-2023-2160
was published
for
modoboa
(pip)
Apr 18, 2023
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
High
Unreviewed
CVE-2024-47221
was published
Sep 22, 2024
Possible
External Service Interaction attack
in eDirectory has been discovered in
OpenText™...
High
Unreviewed
CVE-2021-38133
was published
Sep 12, 2024
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via...
Critical
Unreviewed
CVE-2023-29974
was published
Nov 8, 2023
A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote...
High
Unreviewed
CVE-2022-39997
was published
Aug 27, 2024
Silverpeas vulnerable to password complexity rule bypass
Low
CVE-2024-42850
was published
for
org.silverpeas.core:silverpeas-core
(Maven)
Aug 16, 2024
An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords...
High
Unreviewed
CVE-2024-36789
was published
Jun 7, 2024
IBM Common Licensing 9.0 does not require that users should have strong passwords by default,...
High
Unreviewed
CVE-2024-40697
was published
Aug 13, 2024
A vulnerability has been identified in Location Intelligence family (All versions < V4.4)....
Moderate
Unreviewed
CVE-2024-41683
was published
Aug 13, 2024
Philips Vue PACS does not require that users have strong passwords, which could make it easier...
Moderate
Unreviewed
CVE-2023-40539
was published
Jul 18, 2024
Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to...
High
Unreviewed
CVE-2024-25729
was published
Mar 8, 2024
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain...
Critical
Unreviewed
CVE-2023-24049
was published
Dec 5, 2023
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the...
High
Unreviewed
CVE-2020-11925
was published
May 24, 2022
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly...
Moderate
Unreviewed
CVE-2024-35137
was published
Jun 28, 2024
ProTip!
Advisories are also available from the
GraphQL API