GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
631 advisories
Filter by severity
A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This...
Low
Unreviewed
CVE-2023-3763
was published
Jul 19, 2023
Ironic and ironic-inspector may expose as ConfigMaps
Moderate
CVE-2023-30841
was published
for
github.com/metal3-io/baremetal-operator
(Go)
Apr 26, 2023
A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as...
Low
Unreviewed
CVE-2023-5461
was published
Oct 9, 2023
html inputs of type password recorded in plaintext when converted to text inputs
Moderate
CVE-2023-33187
was published
for
highlight.run
(npm)
May 26, 2023
KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations....
Moderate
Unreviewed
CVE-2021-31855
was published
May 24, 2022
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open...
Moderate
Unreviewed
CVE-2021-3774
was published
May 24, 2022
A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the...
Low
Unreviewed
CVE-2023-5035
was published
Nov 2, 2023
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows...
Moderate
Unreviewed
CVE-2023-0001
was published
Feb 8, 2023
Keycloak vulnerable to Plaintext Storage of User Password
High
CVE-2023-4918
was published
for
org.keycloak:keycloak-core
(Maven)
Sep 12, 2023
A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the...
Low
Unreviewed
CVE-2023-43503
was published
Nov 14, 2023
Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee...
Moderate
Unreviewed
CVE-2021-23884
was published
May 24, 2022
Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for...
Moderate
Unreviewed
CVE-2020-7308
was published
May 24, 2022
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length...
High
Unreviewed
CVE-2017-7252
was published
Nov 3, 2023
SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the...
Moderate
Unreviewed
CVE-2021-32456
was published
May 24, 2022
Cleartext Storage of Sensitive Information in Jenkins Build Notifications Plugin
Low
CVE-2022-34801
was published
for
tools.devnull:build-notifications
(Maven)
Jul 1, 2022
Cleartext Transmission of Sensitive Information in Jenkins Configuration as Code Plugin
Moderate
CVE-2019-10363
was published
for
io.jenkins:configuration-as-code
(Maven)
May 24, 2022
Missing permission checks in Jenkins P4 Plugin
Moderate
CVE-2020-2142
was published
for
org.jenkins-ci.plugins:p4
(Maven)
May 24, 2022
The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated...
Critical
Unreviewed
CVE-2023-39172
was published
Dec 7, 2023
Jenkins Inedo ProGet Plugin Plugin has Cleartext Transmission of Sensitive Information
Low
CVE-2019-10412
was published
for
com.inedo.proget:inedo-proget
(Maven)
May 24, 2022
Credentials transmitted in plain text by Backlog Plugin
Low
CVE-2020-2153
was published
for
org.jenkins-ci.plugins:backlog
(Maven)
May 24, 2022
Credentials transmitted in plain text by Jenkins Logstash Plugin
Low
CVE-2020-2143
was published
for
org.jenkins-ci.plugins:logstash
(Maven)
May 24, 2022
Jenkins Email Extension Plugin SMTP password transmitted and displayed in plain text
Low
CVE-2020-2232
was published
for
org.jenkins-ci.plugins:email-ext
(Maven)
May 24, 2022
An attacker with network access could perform a man-in-the-middle (MitM) attack and capture...
Moderate
Unreviewed
CVE-2023-50703
was published
Dec 20, 2023
On affected platforms running Arista MOS, the configuration of a BGP password will cause the...
Moderate
Unreviewed
CVE-2023-24547
was published
Dec 6, 2023
Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to...
Moderate
Unreviewed
CVE-2023-42579
was published
Dec 5, 2023
ProTip!
Advisories are also available from the
GraphQL API