GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
519 advisories
Filter by severity
openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the...
High
Unreviewed
CVE-2026-81688
was published
Aug 27, 2026
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB...
Critical
Unreviewed
CVE-2026-81681
was published
Aug 27, 2026
DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth...
Critical
Unreviewed
CVE-2026-77812
was published
Aug 21, 2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents,...
High
Unreviewed
CVE-2025-59325
was published
Aug 12, 2026
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent...
High
Unreviewed
CVE-2026-21079
was published
Aug 10, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS...
High
Unreviewed
CVE-2026-20157
was published
Jul 15, 2026
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
High
CVE-2026-54784
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
Moderate
CVE-2026-55568
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations
Moderate
CVE-2026-53442
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
High
CVE-2026-34486
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 9, 2026
Antrea has Missing Encryption of Sensitive Data
High
CVE-2026-34992
was published
for
antrea.io/antrea
(Go)
Apr 3, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure
Critical
CVE-2026-27944
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 5, 2026
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Moderate
CVE-2022-21951
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due...
Moderate
Unreviewed
CVE-2025-15548
was published
Jan 29, 2026
A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with...
High
Unreviewed
CVE-2025-13453
was published
Jan 15, 2026
Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X....
Critical
Unreviewed
CVE-2025-36751
was published
Dec 13, 2025
When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS...
High
Unreviewed
CVE-2025-13053
was published
Dec 12, 2025
The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical...
Moderate
Unreviewed
CVE-2025-65825
was published
Dec 10, 2025
Jenkins Curseforge Publisher Plugin does not mask API Keys displayed on the job configuration form
Moderate
CVE-2025-64147
was published
for
org.jenkins-ci.plugins:curseforge-publisher
(Maven)
Oct 29, 2025
Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml files
Moderate
CVE-2025-64144
was published
for
io.jenkins.plugins:byteguard-build-actions
(Maven)
Oct 29, 2025
Jenkins Curseforge Publisher Plugin stores API Keys unencrypted in job config.xml files
Moderate
CVE-2025-64146
was published
for
org.jenkins-ci.plugins:curseforge-publisher
(Maven)
Oct 29, 2025
Jenkins OpenShift Pipeline Plugin stores authorization tokens unencrypted in job config.xml files
Moderate
CVE-2025-64143
was published
for
com.openshift.jenkins:openshift-pipeline
(Maven)
Oct 29, 2025
Jenkins ByteGuard Build Actions Plugin does not mask API tokens displayed on the job configuration form
Moderate
CVE-2025-64145
was published
for
io.jenkins.plugins:byteguard-build-actions
(Maven)
Oct 29, 2025
An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows...
High
Unreviewed
CVE-2025-48981
was published
Oct 8, 2025
ProTip!
Advisories are also available from the
GraphQL API