GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,128
NuGet
735
pip
3,944
Pub
12
RubyGems
945
Rust
1,024
Swift
39
Unreviewed advisories
All unreviewed
5,000+
640 advisories
Filter by severity
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only...
Moderate
Unreviewed
CVE-2022-26390
was published
Sep 10, 2022
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
High
Unreviewed
CVE-2022-48073
was published
Jan 27, 2023
HCL Launch may store certain data for recurring activities in a plain text format.
Moderate
Unreviewed
CVE-2022-27549
was published
Jul 7, 2022
LibreOffice supports the storage of passwords for web connections in the user’s configuration...
High
Unreviewed
CVE-2022-26307
was published
Jul 26, 2022
Apache OpenOffice supports the storage of passwords for web connections in the user's...
High
Unreviewed
CVE-2022-37401
was published
Aug 16, 2022
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190...
High
Unreviewed
CVE-2022-2739
was published
Sep 2, 2022
Rich Text Edit Control Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2021-40454
was published
May 24, 2022
Centreon Sensitive Data Exposure
Moderate
CVE-2019-17106
was published
for
centreon/centreon
(Composer)
May 24, 2022
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the...
Moderate
Unreviewed
CVE-2020-9407
was published
May 24, 2022
"IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in...
Moderate
Unreviewed
CVE-2021-39077
was published
Nov 4, 2022
Cleartext Storage of Sensitive Information in Jenkins Extensive Testing Plugin
High
CVE-2019-10448
was published
for
jenkins.xtc:extensivetesting
(Maven)
May 24, 2022
Passwords stored in plain text by Jenkins Artifactory Plugin
Low
CVE-2020-2164
was published
for
org.jenkins-ci.plugins:artifactory
(Maven)
May 24, 2022
Jenkins Zephyr for JIRA Test Management Plugin stores credentials in plain text
Low
CVE-2020-2154
was published
for
org.jenkins-ci.plugins:zephyr-for-jira-test-management
(Maven)
May 24, 2022
Jenkins Port Allocator Plugin stores credentials in plain text
Moderate
CVE-2019-10350
was published
for
org.jenkins-ci.plugins:port-allocator
(Maven)
May 24, 2022
Jenkins Caliper CI Plugin stores credentials in plain text
Moderate
CVE-2019-10351
was published
for
com.brianfromoregon:caliper-ci
(Maven)
May 24, 2022
Jenkins View26 Test-Reporting Plugin stores access token in plain text
Moderate
CVE-2019-10452
was published
for
org.jenkins-ci.plugins:view26
(Maven)
May 24, 2022
Passwords stored in plain text by ElasTest Plugin
Moderate
CVE-2020-2274
was published
for
org.jenkins-ci.plugins:elastest
(Maven)
May 24, 2022
Jenkins Sofy.AI Plugin stores API token in plain text
Moderate
CVE-2019-10447
was published
for
io.jenkins.plugins:sofy-ai
(Maven)
May 24, 2022
Jenkins SOASTA CloudTest Plugin stores API token in plain text
Moderate
CVE-2019-10451
was published
for
com.soasta.jenkins:cloudtest
(Maven)
May 24, 2022
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in...
Moderate
Unreviewed
CVE-2020-25678
was published
May 24, 2022
A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and...
Low
Unreviewed
CVE-2023-2863
was published
May 24, 2023
Weave GitOps Terraform Controller Information Disclosure Vulnerability
High
CVE-2023-34236
was published
for
github.com/weaveworks/tf-controller
(Go)
Jul 14, 2023
A vulnerability was found in Intergard SGS 8.7.0. It has been classified as problematic. This...
Moderate
Unreviewed
CVE-2023-3762
was published
Jul 19, 2023
Data written to GitHub Actions Cache may expose secrets
High
CVE-2023-30853
was published
for
gradle/gradle-build-action
(GitHub Actions)
May 1, 2023
Strapi leaking sensitive user information by filtering on private fields
High
CVE-2023-22894
was published
for
@strapi/strapi
(npm)
Apr 19, 2023
ProTip!
Advisories are also available from the
GraphQL API