Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

236 advisories

@nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys Critical
GHSA-84c3-j8r2-mcm8 was published for @nfid/embed (npm) Feb 26, 2024
agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate` Critical
CVE-2024-1631 was published for @dfinity/auth-client (npm) Feb 21, 2024
peterpeterparker krpeacock
Use of Insufficiently Random Values in github.com/greenpau/caddy-security Moderate
CVE-2024-21495 was published for github.com/greenpau/caddy-security (Go) Feb 17, 2024
Insecure random string generator used for sensitive data Moderate
CVE-2023-46740 was published for github.com/cubefs/cubefs (Go) Jan 3, 2024
AdamKorcz
PyPinkSign uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption High
CVE-2023-48056 was published for pypinksign (pip) Nov 16, 2023
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random. Critical Unreviewed
CVE-2020-27630 was published Oct 10, 2023
In PicoTCP 1.7.0, TCP ISNs are improperly random. Critical Unreviewed
CVE-2020-27635 was published Oct 10, 2023
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random. Critical Unreviewed
CVE-2020-27631 was published Oct 10, 2023
In Contiki 4.5, TCP ISNs are improperly random. Critical Unreviewed
CVE-2020-27634 was published Oct 10, 2023
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random. Critical Unreviewed
CVE-2020-27636 was published Oct 10, 2023
In FNET 4.6.3, TCP ISNs are improperly random. Critical Unreviewed
CVE-2020-27633 was published Oct 10, 2023
Magento LTS's guest order "protect code" can be brute-forced too easily High
CVE-2023-41879 was published for openmage/magento-lts (Composer) Sep 11, 2023
theroch fballiano
colinmollenhour
ProTip! Advisories are also available from the GraphQL API