GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
641 advisories
Filter by severity
"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which...
Moderate
Unreviewed
CVE-2022-34339
was published
Nov 4, 2022
"IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in...
Moderate
Unreviewed
CVE-2021-39077
was published
Nov 4, 2022
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log...
Moderate
Unreviewed
CVE-2022-2805
was published
Oct 19, 2022
An issue has been discovered in hunter2 affecting all versions before 2.1.0. Improper handling of...
Moderate
Unreviewed
CVE-2022-3540
was published
Oct 17, 2022
Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An...
Moderate
Unreviewed
CVE-2022-33918
was published
Oct 13, 2022
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before...
Moderate
Unreviewed
CVE-2015-1931
was published
Sep 30, 2022
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
Critical
Unreviewed
CVE-2020-15332
was published
Sep 30, 2022
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
Moderate
Unreviewed
CVE-2020-15325
was published
Sep 30, 2022
A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token...
Moderate
Unreviewed
CVE-2022-32217
was published
Sep 25, 2022
Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
Critical
CVE-2021-36782
was published
for
github.com/rancher/rancher
(Go)
Sep 23, 2022
Jenkins BigPanda Notifier Plugin Missing Password Field Masking
Low
CVE-2022-41248
was published
for
org.jenkins-ci.plugins:bigpanda-jenkins
(Maven)
Sep 22, 2022
Shopware contains sensitive data in backend customer module
Moderate
CVE-2022-36101
was published
for
shopware/shopware
(Composer)
Sep 16, 2022
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only...
Moderate
Unreviewed
CVE-2022-26390
was published
Sep 10, 2022
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which...
Moderate
Unreviewed
CVE-2021-39009
was published
Sep 2, 2022
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190...
High
Unreviewed
CVE-2022-2739
was published
Sep 2, 2022
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs...
Moderate
Unreviewed
CVE-2021-3585
was published
Aug 27, 2022
The affected device stores sensitive information in cleartext, which may allow an authenticated...
Moderate
Unreviewed
CVE-2022-2569
was published
Aug 25, 2022
Apache OpenOffice supports the storage of passwords for web connections in the user's...
High
Unreviewed
CVE-2022-37401
was published
Aug 16, 2022
A vulnerability, which was classified as problematic, was found in SourceCodester Guest...
High
Unreviewed
CVE-2022-2813
was published
Aug 16, 2022
Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A...
Moderate
Unreviewed
CVE-2022-29090
was published
Aug 11, 2022
Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability...
High
Unreviewed
CVE-2022-33928
was published
Aug 11, 2022
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an...
High
Unreviewed
CVE-2022-34924
was published
Aug 3, 2022
The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It...
High
Unreviewed
CVE-2022-30275
was published
Jul 27, 2022
LibreOffice supports the storage of passwords for web connections in the user’s configuration...
High
Unreviewed
CVE-2022-26307
was published
Jul 26, 2022
The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed...
High
Unreviewed
CVE-2022-24660
was published
Jul 21, 2022
ProTip!
Advisories are also available from the
GraphQL API