GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
44 advisories
Filter by severity
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an...
Moderate
Unreviewed
CVE-2026-75112
was published
Aug 19, 2026
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition...
Moderate
Unreviewed
CVE-2026-74871
was published
Aug 17, 2026
Flowise has Insufficient Password Salt Rounds
Moderate
CVE-2026-56272
was published
for
flowise
(npm)
Mar 5, 2026
Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords....
Moderate
Unreviewed
CVE-2026-57310
was published
Jul 20, 2026
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
Moderate
Unreviewed
CVE-2022-23348
was published
Mar 22, 2022
NeuVector has an insecure password storage and is vulnerable to rainbow attack
Moderate
CVE-2025-53884
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of...
Moderate
Unreviewed
CVE-2026-9641
was published
Jun 12, 2026
electerm's encrypt method not safe enough
Moderate
CVE-2026-45787
was published
for
electerm
(npm)
May 14, 2026
Danelec MacGregor Voyage Data Recorder
passwords are stored with a hashing method which limits...
Moderate
Unreviewed
CVE-2026-44611
was published
May 29, 2026
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40...
Moderate
Unreviewed
CVE-2008-1526
was published
May 1, 2022
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for...
Moderate
Unreviewed
CVE-2002-1657
was published
Apr 30, 2022
Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could...
Moderate
Unreviewed
CVE-2024-24553
was published
Jun 24, 2024
RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
Moderate
Unreviewed
CVE-2025-67168
was published
Dec 17, 2025
Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS)...
Moderate
Unreviewed
CVE-2025-13532
was published
Dec 16, 2025
A high privileged remote attacker with admin privileges for the webUI can brute-force the "root"...
Moderate
Unreviewed
CVE-2025-41692
was published
Dec 9, 2025
Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router ...
Moderate
Unreviewed
CVE-2025-46413
was published
Nov 7, 2025
Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier...
Moderate
Unreviewed
CVE-2014-2354
was published
May 17, 2022
Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona...
Moderate
Unreviewed
CVE-2024-7701
was published
Dec 15, 2024
A vulnerability in the users configuration file of ctrlX OS may allow a remote authenticated (low...
Moderate
Unreviewed
CVE-2025-24340
was published
Apr 30, 2025
IBM Security Verify Governance 10.0.2 Identity Manager
uses a one-way cryptographic hash...
Moderate
Unreviewed
CVE-2023-33838
was published
Jan 29, 2025
AMI Megarac Weak password hashes for Redfish & API
Moderate
Unreviewed
CVE-2022-40258
was published
Jan 31, 2023
XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted
Moderate
CVE-2024-31464
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 10, 2024
Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements...
Moderate
Unreviewed
CVE-2024-55057
was published
Dec 17, 2024
UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a...
Moderate
Unreviewed
CVE-2019-12737
was published
May 24, 2022
** UNSUPPPORTED WHEN ASSIGNED ** Vulnerability in ekorCCP and ekorRCI that could allow an...
Moderate
Unreviewed
CVE-2022-47557
was published
Sep 19, 2023
ProTip!
Advisories are also available from the
GraphQL API