GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,052
Maven
5,000+
npm
4,793
NuGet
825
pip
4,389
Pub
12
RubyGems
988
Rust
1,146
Swift
50
Unreviewed advisories
All unreviewed
5,000+
120 advisories
Filter by severity
Gradio has an Open Redirect in its OAuth Flow
Moderate
CVE-2026-28415
was published
for
gradio
(pip)
Mar 1, 2026
Fleet: Device lock PIN can be predicted if lock time is known
Moderate
CVE-2026-23999
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
When connecting to the Solax Cloud MQTT server the username is the "registration number", which...
Moderate
Unreviewed
CVE-2025-15574
was published
Feb 12, 2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for...
Moderate
Unreviewed
CVE-2025-11723
was published
Jan 6, 2026
The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all...
Moderate
Unreviewed
CVE-2025-11707
was published
Dec 13, 2025
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-12787
was published
Nov 11, 2025
The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not...
Moderate
Unreviewed
CVE-2025-6515
was published
Oct 20, 2025
The Banhammer – Monitor Site Traffic, Block Bad Users and Bots plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-10745
was published
Sep 26, 2025
A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0....
Moderate
Unreviewed
CVE-2025-6931
was published
Jul 1, 2025
SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt...
Moderate
Unreviewed
CVE-2024-50684
was published
Feb 26, 2025
Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields,...
Moderate
Unreviewed
CVE-2024-10604
was published
Jan 30, 2025
Use of Insufficiently Random Values in undici
Moderate
CVE-2025-22150
was published
for
undici
(npm)
Jan 21, 2025
When batch jobs are executed by pgAgent, a script is created in a temporary directory and then...
Moderate
Unreviewed
CVE-2025-0218
was published
Jan 7, 2025
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature...
Moderate
Unreviewed
CVE-2024-20331
was published
Oct 23, 2024
Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection...
Moderate
Unreviewed
CVE-2024-6348
was published
Aug 19, 2024
A vulnerability, which was classified as problematic, was found in projectsend up to r1605....
Moderate
Unreviewed
CVE-2024-7659
was published
Aug 12, 2024
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow...
Moderate
Unreviewed
CVE-2024-42164
was published
Aug 12, 2024
Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow...
Moderate
Unreviewed
CVE-2024-42165
was published
Aug 12, 2024
The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up...
Moderate
Unreviewed
CVE-2024-5149
was published
Jun 5, 2024
The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2023-6799
was published
Apr 9, 2024
Use of Insufficiently Random Values vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3,...
Moderate
Unreviewed
CVE-2024-28013
was published
Mar 28, 2024
TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure...
Moderate
Unreviewed
CVE-2024-22473
was published
Feb 21, 2024
Use of Insufficiently Random Values in github.com/greenpau/caddy-security
Moderate
CVE-2024-21495
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
Duplicate Advisory: Discovery uses the same AES/GCM Nonce throughout the session
Moderate
GHSA-wp4m-7hpj-8qp8
was published
for
tech.pegasys.discovery:discovery
(Maven)
Jan 20, 2024
•
withdrawn
In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This...
Moderate
Unreviewed
CVE-2023-32831
was published
Jan 2, 2024
ProTip!
Advisories are also available from the
GraphQL API