GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
166 advisories
Filter by severity
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users'...
Low
Unreviewed
CVE-2020-8956
was published
May 24, 2022
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify...
Moderate
Unreviewed
CVE-2020-27585
was published
May 24, 2022
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not...
High
Unreviewed
CVE-2020-25153
was published
May 24, 2022
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access...
Moderate
Unreviewed
CVE-2020-27587
was published
May 24, 2022
Versions of the Official teamspeak Docker images through 3.6.0 contain a blank password for the...
Critical
Unreviewed
CVE-2020-29590
was published
May 24, 2022
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the...
Critical
Unreviewed
CVE-2020-29591
was published
May 24, 2022
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external...
Moderate
Unreviewed
CVE-2020-8296
was published
May 24, 2022
A weak password requirement vulnerability exists in the Create New User function of MintHCM...
Critical
Unreviewed
CVE-2021-25839
was published
May 24, 2022
An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker...
Critical
Unreviewed
CVE-2021-26797
was published
May 24, 2022
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long...
High
Unreviewed
CVE-2022-29700
was published
Apr 28, 2022
A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could...
Moderate
Unreviewed
CVE-2021-1522
was published
May 24, 2022
IBM Security Guardium 11.2 does not require that users should have strong passwords by default,...
Critical
Unreviewed
CVE-2021-20418
was published
May 24, 2022
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password...
High
Unreviewed
CVE-2022-27558
was published
Aug 29, 2022
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because...
Moderate
Unreviewed
CVE-2021-28914
was published
May 24, 2022
ECOA BAS controller uses weak set of default administrative credentials that can be easily...
Critical
Unreviewed
CVE-2021-41296
was published
May 24, 2022
The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and...
Critical
Unreviewed
CVE-2021-35498
was published
May 24, 2022
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient...
Critical
Unreviewed
CVE-2021-38462
was published
May 24, 2022
phpMyFAQ contains Weak Password Requirements
Critical
CVE-2022-3754
was published
for
thorsten/phpmyfaq
(Composer)
Oct 29, 2022
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace...
High
Unreviewed
CVE-2021-36808
was published
May 24, 2022
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before...
High
Unreviewed
CVE-2020-15369
was published
May 24, 2022
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not...
High
Unreviewed
CVE-2021-25923
was published
May 24, 2022
Raneto v0.17.0 employs weak password complexity requirements
Critical
CVE-2022-35143
was published
for
raneto
(npm)
Aug 5, 2022
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting,...
Critical
Unreviewed
CVE-2022-45482
was published
Dec 2, 2022
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
Critical
Unreviewed
CVE-2022-3268
was published
Sep 23, 2022
Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the...
High
Unreviewed
CVE-2022-34772
was published
Aug 23, 2022
ProTip!
Advisories are also available from the
GraphQL API