GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,489
Maven
5,000+
npm
5,000+
NuGet
892
pip
4,745
Pub
13
RubyGems
1,033
Rust
1,228
Swift
53
Unreviewed advisories
All unreviewed
5,000+
49 advisories
Filter by severity
Auth0 Symfony SDK has Insufficient Entropy in Cookie Encryption
High
GHSA-ghc5-95c2-vwcv
was published
for
auth0/symfony
(Composer)
Apr 3, 2026
Auth0 WordPress Plugin has Insufficient Entropy in Cookie Encryption
High
GHSA-vfpx-q664-h93m
was published
for
auth0/wordpress
(Composer)
Apr 3, 2026
Auth0 laravel-auth0 SDK has Insufficient Entropy in Cookie Encryption
High
GHSA-fmg6-246m-9g2v
was published
for
auth0/login
(Composer)
Apr 3, 2026
Auth0 PHP SDK has Insufficient Entropy in Cookie Encryption
High
CVE-2026-34236
was published
for
auth0/auth0-php
(Composer)
Apr 1, 2026
libcrux has All-Zero Key Generation Upon Catastrophic RNG Failure
High
GHSA-434v-x5qv-pmh6
was published
for
libcrux-ed25519
(Rust)
Mar 26, 2026
Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the...
High
Unreviewed
CVE-2026-1814
was published
Feb 3, 2026
A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent...
High
Unreviewed
CVE-2025-13399
was published
Jan 29, 2026
SM2-PKE has 32-bit Biased Nonce Vulnerability
High
CVE-2026-22698
was published
for
sm2
(Rust)
Jan 9, 2026
Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID...
High
Unreviewed
CVE-2020-36925
was published
Jan 6, 2026
VPN Firewall developed by QNO Technology has a Insufficient Entropy vulnerability, allowing...
High
Unreviewed
CVE-2025-15387
was published
Dec 31, 2025
The Litmus platform uses JWT for authentication and authorization, but the secret being used for...
High
Unreviewed
CVE-2025-14261
was published
Dec 8, 2025
CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when...
High
Unreviewed
CVE-2025-50122
was published
Jul 11, 2025
Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy...
High
Unreviewed
CVE-2025-1860
was published
Mar 28, 2025
Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private...
High
Unreviewed
CVE-2025-29311
was published
Mar 24, 2025
Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not...
High
Unreviewed
CVE-2025-1828
was published
Mar 11, 2025
Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV...
High
Unreviewed
CVE-2024-53522
was published
Jan 7, 2025
Eufy HomeBase 2 model T8010X v3.2.8.3h was discovered to use the deprecated wireless protocol...
High
Unreviewed
CVE-2023-37822
was published
Oct 3, 2024
Zendframework Potential Information Disclosure and Insufficient Entropy vulnerability
High
GHSA-848f-mph5-9pm9
was published
for
zendframework/zendframework1
(Composer)
Jun 7, 2024
ZendFramework1 Potential Insufficient Entropy Vulnerability
High
GHSA-8xhv-gqm4-3w99
was published
for
zendframework/zendframework1
(Composer)
Jun 7, 2024
Zend-Captcha Information Disclosure and Insufficient Entropy vulnerability
High
GHSA-mg4x-prh7-g4mx
was published
for
zendframework/zend-captcha
(Composer)
Jun 7, 2024
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction...
High
Unreviewed
CVE-2024-25407
was published
Feb 13, 2024
An insufficient entropy vulnerability was identified in GitHub Enterprise Server (GHES) that...
High
Unreviewed
CVE-2023-46648
was published
Dec 21, 2023
An Insufficient Entropy vulnerability in the Schweitzer Engineering Laboratories SEL-451 could...
High
Unreviewed
CVE-2023-31176
was published
Nov 30, 2023
jose4j uses weak cryptographic algorithm
High
CVE-2023-31582
was published
for
org.bitbucket.b_c:jose4j
(Maven)
Oct 25, 2023
A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom...
High
Unreviewed
CVE-2023-20107
was published
Mar 23, 2023
ProTip!
Advisories are also available from the
GraphQL API