GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
489 advisories
Filter by severity
DragonFly's tiny file download uses hard coded HTTP protocol
Moderate
CVE-2025-59410
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon...
Moderate
Unreviewed
CVE-2025-10227
was published
Sep 10, 2025
HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms...
Moderate
Unreviewed
CVE-2025-31977
was published
Aug 28, 2025
Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to...
High
Unreviewed
CVE-2025-48862
was published
Aug 14, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
Moderate
Unreviewed
CVE-2024-41982
was published
Aug 12, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
Low
Unreviewed
CVE-2024-41980
was published
Aug 12, 2025
pyjwt v2.10.1 was discovered to contain weak encryption.
High
Unreviewed
CVE-2025-45768
was published
Jul 31, 2025
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43274
was published
Jul 30, 2025
Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the...
Moderate
Unreviewed
CVE-2025-40680
was published
Jul 25, 2025
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information...
Moderate
Unreviewed
CVE-2025-33020
was published
Jul 23, 2025
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22
could be vulnerable to information...
Moderate
Unreviewed
CVE-2025-36062
was published
Jul 21, 2025
An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0.16.0. A...
High
Unreviewed
CVE-2025-32874
was published
Jul 16, 2025
Jenkins User1st uTester Plugin vulnerability exposes unencrypted token to authenticated users
Low
CVE-2025-53678
was published
for
io.jenkins.plugins:user1st-utester
(Maven)
Jul 9, 2025
Jenkins Xooa Plugin vulnerability exposes unencrypted tokens to authenticated users
Moderate
CVE-2025-53676
was published
for
io.jenkins.plugins:xooa
(Maven)
Jul 9, 2025
Jenkins Sensedia API Platform Plugin vulnerability exposes unencrypted tokens in its global configuration file
Moderate
CVE-2025-53673
was published
for
org.jenkins-ci.plugins:sensedia-api-platform
(Maven)
Jul 9, 2025
Jenkins Dead Man's Snitch Plugin vulnerability stores tokens in plain text
Moderate
CVE-2025-53666
was published
for
org.jenkins-ci.plugins:deadmanssnitch
(Maven)
Jul 9, 2025
Jenkins IBM Cloud DevOps Plugin vulnerability exposes SonarQube authentication tokens
Moderate
CVE-2025-53663
was published
for
com.ibm.devops:ibm-cloud-devops
(Maven)
Jul 9, 2025
Jenkins QMetry Test Management Plugin stores unencrypted API keys
Moderate
CVE-2025-53659
was published
for
org.jenkins-ci.plugins:qmetry-test-management
(Maven)
Jul 9, 2025
Jenkins VAddy Plugin vulnerability exposes unencrypted keys to certain authenticated users
Moderate
CVE-2025-53668
was published
for
org.jenkins-ci.plugins:vaddy-plugin
(Maven)
Jul 9, 2025
Jenkins Aqua Security Scanner Plugin vulnerability exposes scanner tokens
Moderate
CVE-2025-53653
was published
for
org.jenkins-ci.plugins:aqua-security-scanner
(Maven)
Jul 9, 2025
git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes
was set, and the remote...
High
Unreviewed
CVE-2014-6274
was published
Jun 26, 2025
A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions),...
High
Unreviewed
CVE-2025-24008
was published
May 13, 2025
Milestone Systems has discovered a
security vulnerability in Milestone XProtect installer that...
Moderate
Unreviewed
CVE-2025-1688
was published
Apr 15, 2025
Jenkins AsakusaSatellite Plugin Does not Mask API Keys via Job Configuration Form
Moderate
CVE-2025-31728
was published
for
org.codefirst.jenkins.asakusasatellite:asakusa-satellite-plugin
(Maven)
Apr 2, 2025
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2...
Moderate
Unreviewed
CVE-2023-37405
was published
Mar 27, 2025
ProTip!
Advisories are also available from the
GraphQL API