GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,233
Erlang
31
GitHub Actions
20
Go
1,992
Maven
5,000+
npm
3,709
NuGet
661
pip
3,346
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
35 advisories
Filter by severity
A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic....
Moderate
Unreviewed
CVE-2024-3735
was published
Apr 13, 2024
Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password...
Moderate
Unreviewed
CVE-2024-51398
was published
Nov 1, 2024
D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password,...
Moderate
Unreviewed
CVE-2024-48272
was published
Oct 30, 2024
HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network...
Moderate
Unreviewed
CVE-2024-21865
was published
Mar 25, 2024
In the goTenna Pro ATAK Plugin application, the encryption keys are
stored along with a static...
Moderate
Unreviewed
CVE-2024-45374
was published
Sep 26, 2024
The goTenna Pro series uses a weak password for the QR broadcast message. If the QR broadcast...
Moderate
Unreviewed
CVE-2024-47121
was published
Sep 26, 2024
A vulnerability has been identified in Location Intelligence family (All versions < V4.4)....
Moderate
Unreviewed
CVE-2024-41683
was published
Aug 13, 2024
Philips Vue PACS does not require that users have strong passwords, which could make it easier...
Moderate
Unreviewed
CVE-2023-40539
was published
Jul 18, 2024
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly...
Moderate
Unreviewed
CVE-2024-35137
was published
Jun 28, 2024
The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak...
Moderate
Unreviewed
CVE-2024-32213
was published
May 1, 2024
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks...
Moderate
Unreviewed
CVE-2018-5389
was published
May 13, 2022
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password...
Moderate
Unreviewed
CVE-2023-3470
was published
Aug 2, 2023
IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2024-22355
was published
Mar 3, 2024
IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have...
Moderate
Unreviewed
CVE-2023-50305
was published
Mar 1, 2024
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability...
Moderate
Unreviewed
CVE-2024-1345
was published
Feb 19, 2024
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability...
Moderate
Unreviewed
CVE-2024-1346
was published
Feb 19, 2024
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by...
Moderate
Unreviewed
CVE-2020-4574
was published
May 24, 2022
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker...
Moderate
Unreviewed
CVE-2023-38369
was published
Feb 7, 2024
Weak password requirement vulnerability
in Lamassu Bitcoin ATM Douro machines, in its 7.1...
Moderate
Unreviewed
CVE-2024-0676
was published
Jan 30, 2024
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1...
Moderate
Unreviewed
CVE-2023-3423
was published
Jun 27, 2023
A flaw was found in Samba, all versions starting samba 4.5.0 until samba 4.9.15, samba 4.10.10,...
Moderate
Unreviewed
CVE-2019-14833
was published
May 24, 2022
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in...
Moderate
Unreviewed
CVE-2019-19093
was published
May 24, 2022
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0...
Moderate
Unreviewed
CVE-2021-36689
was published
Mar 4, 2023
** DISPUTED ** Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it...
Moderate
Unreviewed
CVE-2017-7305
was published
May 13, 2022
** DISPUTED ** Riverbed RiOS through 9.6.0 has a weak default password for the secure vault,...
Moderate
Unreviewed
CVE-2017-7306
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API