GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
640 advisories
Filter by severity
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 all...
High
Unreviewed
CVE-2022-25164
was published
Nov 25, 2022
The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password...
High
Unreviewed
CVE-2022-24188
was published
Nov 29, 2022
IXPdata EasyInstall 6.6.14725 contains an access control issue.
High
Unreviewed
CVE-2022-35120
was published
Dec 2, 2022
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through...
Moderate
Unreviewed
CVE-2022-4312
was published
Dec 12, 2022
The vCenter Server contains an information disclosure vulnerability due to the logging of...
Moderate
Unreviewed
CVE-2022-31697
was published
Dec 13, 2022
Sensitive information was stored in plain text in a file that is accessible by a user with a...
Moderate
Unreviewed
CVE-2022-47512
was published
Dec 19, 2022
Logins saved by Firefox should be managed by the Password Manager component which uses encryption...
Low
Unreviewed
CVE-2022-42931
was published
Dec 22, 2022
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including...
Moderate
Unreviewed
CVE-2022-22457
was published
Dec 23, 2022
Certain General Electric Renewable Energy products store cleartext credentials in flash memory....
Moderate
Unreviewed
CVE-2022-24120
was published
Dec 26, 2022
An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the...
High
Unreviewed
CVE-2022-37785
was published
Jan 1, 2023
IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access...
Moderate
Unreviewed
CVE-2022-41740
was published
Jan 5, 2023
Apache James MIME4J vulnerable to information disclosure to local users
Moderate
CVE-2022-45787
was published
for
org.apache.james:apache-mime4j-storage
(Maven)
Jan 6, 2023
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read...
Moderate
Unreviewed
CVE-2022-22470
was published
Jan 9, 2023
NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This...
Moderate
Unreviewed
CVE-2022-42284
was published
Jan 13, 2023
A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0...
Moderate
Unreviewed
CVE-2022-45439
was published
Jan 17, 2023
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in...
High
Unreviewed
CVE-2022-38112
was published
Jan 20, 2023
** DISPUTED ** KeePass through 2.53 (in a default installation) allows an attacker, who has write...
Moderate
Unreviewed
CVE-2023-24055
was published
Jan 22, 2023
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects
High
CVE-2022-43757
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
Plaintext Storage of a Password in Jenkins JIRA Pipeline Steps Plugin
Moderate
CVE-2023-24439
was published
for
org.jenkins-ci.plugins:jira-steps
(Maven)
Jan 26, 2023
Plaintext Storage of a Password in Jenkins TestQuality Updater Plugin
Moderate
CVE-2023-24454
was published
for
org.jenkins-ci.plugins:testquality-updater
(Maven)
Jan 26, 2023
Passwords stored in plain text by Jenkins view-cloner Plugin
Moderate
CVE-2023-24450
was published
for
org.jenkins-ci.plugins:view-cloner
(Maven)
Jan 26, 2023
Plaintext storage of Access Token in Jenkins GitHub Pull Request Coverage Status Plugin
Moderate
CVE-2023-24442
was published
for
org.jenkins-ci.plugins:github-pr-coverage-status
(Maven)
Jan 26, 2023
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
High
CVE-2015-8314
was published
for
devise
(RubyGems)
Jan 26, 2023
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
High
Unreviewed
CVE-2022-48071
was published
Jan 27, 2023
Phicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.
High
Unreviewed
CVE-2022-48073
was published
Jan 27, 2023
ProTip!
Advisories are also available from the
GraphQL API