GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
109 advisories
Filter by severity
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus...
High
Unreviewed
CVE-2026-81704
was published
Aug 27, 2026
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF...
High
Unreviewed
CVE-2026-81689
was published
Aug 27, 2026
FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin...
High
Unreviewed
CVE-2026-80211
was published
Aug 27, 2026
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an...
Moderate
Unreviewed
CVE-2026-75112
was published
Aug 19, 2026
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition...
Moderate
Unreviewed
CVE-2026-74871
was published
Aug 17, 2026
The root password hash of the device can be obtained through unencrypted information in the...
Low
Unreviewed
CVE-2026-49005
was published
Aug 7, 2026
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker...
High
Unreviewed
CVE-2026-5040
was published
Jul 14, 2026
Flowise has Insufficient Password Salt Rounds
Moderate
CVE-2026-56272
was published
for
flowise
(npm)
Mar 5, 2026
Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords....
Moderate
Unreviewed
CVE-2026-57310
was published
Jul 20, 2026
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
Moderate
Unreviewed
CVE-2022-23348
was published
Mar 22, 2022
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long...
High
Unreviewed
CVE-2020-28873
was published
May 24, 2022
NeuVector has an insecure password storage and is vulnerable to rainbow attack
Moderate
CVE-2025-53884
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
Authentication Bypass by Capture-replay, Use of Password Hash With Insufficient Computational...
Critical
Unreviewed
CVE-2026-30789
was published
Mar 5, 2026
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of...
Moderate
Unreviewed
CVE-2026-9641
was published
Jun 12, 2026
electerm's encrypt method not safe enough
Moderate
CVE-2026-45787
was published
for
electerm
(npm)
May 14, 2026
QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm...
High
Unreviewed
CVE-2026-25861
was published
Jun 3, 2026
Danelec MacGregor Voyage Data Recorder
passwords are stored with a hashing method which limits...
Moderate
Unreviewed
CVE-2026-44611
was published
May 29, 2026
LiteLLM: Password hash exposure and pass-the-hash authentication bypass
High
GHSA-69x8-hrgq-fjj8
was published
for
litellm
(pip)
Apr 8, 2026
Liferay Portal defaults to a low work factor for the default password hashing algorithm
High
CVE-2024-25607
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Feb 20, 2024
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40...
Moderate
Unreviewed
CVE-2008-1526
was published
May 1, 2022
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting...
High
Unreviewed
CVE-2001-0967
was published
Apr 30, 2022
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for...
Moderate
Unreviewed
CVE-2002-1657
was published
Apr 30, 2022
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the...
High
Unreviewed
CVE-2005-0408
was published
May 1, 2022
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local...
Low
Unreviewed
CVE-2006-1058
was published
May 1, 2022
Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could...
Moderate
Unreviewed
CVE-2024-24553
was published
Jun 24, 2024
ProTip!
Advisories are also available from the
GraphQL API