GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,485
Maven
5,000+
npm
4,104
NuGet
734
pip
3,918
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
100 advisories
Filter by severity
The Thinbus Javascript Secure Remote Password (SRP) Client Generates Fewer Bits of Entropy Than Intended
Moderate
CVE-2025-54885
was published
for
thinbus-srp
(npm)
Aug 6, 2025
CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when...
High
Unreviewed
CVE-2025-50122
was published
Jul 11, 2025
WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of...
Moderate
Unreviewed
CVE-2024-52322
was published
Apr 7, 2025
Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of...
Moderate
Unreviewed
CVE-2024-58036
was published
Apr 7, 2025
Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy,...
Moderate
Unreviewed
CVE-2024-57868
was published
Apr 7, 2025
Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy,...
Moderate
Unreviewed
CVE-2024-56370
was published
Apr 5, 2025
Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy...
High
Unreviewed
CVE-2025-1860
was published
Mar 28, 2025
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt...
Moderate
Unreviewed
CVE-2025-27552
was published
Mar 26, 2025
DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt...
Moderate
Unreviewed
CVE-2025-27551
was published
Mar 26, 2025
Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private...
High
Unreviewed
CVE-2025-29311
was published
Mar 24, 2025
The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they...
Moderate
Unreviewed
CVE-2024-9055
was published
Mar 17, 2025
Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not...
High
Unreviewed
CVE-2025-1828
was published
Mar 11, 2025
Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV...
High
Unreviewed
CVE-2024-53522
was published
Jan 7, 2025
In RsaKeyPairGenerator::getNumberOfIterations of RSAKeyPairGenerator.java, an incorrect...
Moderate
Unreviewed
CVE-2018-9426
was published
Dec 3, 2024
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature...
Moderate
Unreviewed
CVE-2024-20331
was published
Oct 23, 2024
The devices are vulnerable to session hijacking due to insufficient
entropy in its session ID...
Critical
Unreviewed
CVE-2024-47945
was published
Oct 15, 2024
Eufy HomeBase 2 model T8010X v3.2.8.3h was discovered to use the deprecated wireless protocol...
High
Unreviewed
CVE-2023-37822
was published
Oct 3, 2024
Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length
Moderate
CVE-2024-8796
was published
for
devise-two-factor
(RubyGems)
Sep 17, 2024
An insufficient entropy vulnerability caused by the improper use of a randomness function with...
Moderate
Unreviewed
CVE-2024-38270
was published
Sep 10, 2024
Openshift Console insufficient entropy vulnerability
Moderate
CVE-2024-6508
was published
for
github.com/openshift/console
(Go)
Aug 21, 2024
Zendframework Potential Information Disclosure and Insufficient Entropy vulnerability
High
GHSA-848f-mph5-9pm9
was published
for
zendframework/zendframework1
(Composer)
Jun 7, 2024
ZendFramework1 Potential Insufficient Entropy Vulnerability
High
GHSA-8xhv-gqm4-3w99
was published
for
zendframework/zendframework1
(Composer)
Jun 7, 2024
Zend-Captcha Information Disclosure and Insufficient Entropy vulnerability
High
GHSA-mg4x-prh7-g4mx
was published
for
zendframework/zend-captcha
(Composer)
Jun 7, 2024
ZendFramework Information Disclosure and Insufficient Entropy vulnerability
Moderate
GHSA-2fhr-8r8r-qp56
was published
for
zendframework/zendframework
(Composer)
Jun 7, 2024
An issue was discovered in Samsung Mobile Processor, Automotive Processor, Wearable Processor,...
Moderate
Unreviewed
CVE-2023-49927
was published
Jun 5, 2024
ProTip!
Advisories are also available from the
GraphQL API