GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
641 advisories
Filter by severity
Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access...
High
Unreviewed
CVE-2022-30626
was published
Jul 19, 2022
HCL Launch may store certain data for recurring activities in a plain text format.
Moderate
Unreviewed
CVE-2022-27549
was published
Jul 7, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in...
Moderate
Unreviewed
CVE-2022-22366
was published
Jul 2, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive...
Moderate
Unreviewed
CVE-2022-22367
was published
Jul 2, 2022
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text...
Moderate
Unreviewed
CVE-2022-22478
was published
Jul 1, 2022
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
Moderate
Unreviewed
CVE-2021-41639
was published
Jun 25, 2022
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4...
High
Unreviewed
CVE-2021-45025
was published
Jun 18, 2022
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as...
Moderate
Unreviewed
CVE-2017-20040
was published
Jun 12, 2022
** DISPUTED ** FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH...
Moderate
Unreviewed
CVE-2022-29620
was published
Jun 8, 2022
E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND...
Moderate
Unreviewed
CVE-2022-23236
was published
Jun 3, 2022
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs,...
Critical
Unreviewed
CVE-2021-29954
was published
May 24, 2022
UltraLog Express device management software stores user’s information in cleartext. Any user can...
Moderate
Unreviewed
CVE-2020-3921
was published
May 24, 2022
ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the...
High
Unreviewed
CVE-2021-41302
was published
May 24, 2022
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data...
High
Unreviewed
CVE-2021-35526
was published
May 24, 2022
During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor...
Moderate
Unreviewed
CVE-2020-9045
was published
May 24, 2022
Secom Co. Dr.ID, a Door Access Control and Personnel Attendance Management system, stores users’...
Moderate
Unreviewed
CVE-2020-3935
was published
May 24, 2022
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in...
Moderate
Unreviewed
CVE-2019-4314
was published
May 24, 2022
Jenkins NeuVector Vulnerability Scanner Plugin stored credentials in plain text
Moderate
CVE-2019-10430
was published
for
io.jenkins.plugins:neuvector-vulnerability-scanner
(Maven)
May 24, 2022
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text...
Low
Unreviewed
CVE-2019-4566
was published
May 24, 2022
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which...
Moderate
Unreviewed
CVE-2021-38949
was published
May 24, 2022
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config...
High
Unreviewed
CVE-2021-37157
was published
May 24, 2022
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The...
Moderate
Unreviewed
CVE-2020-10053
was published
May 24, 2022
A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because...
High
Unreviewed
CVE-2021-42370
was published
May 24, 2022
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov...
Moderate
Unreviewed
CVE-2021-25502
was published
May 24, 2022
Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext,...
High
Unreviewed
CVE-2021-38422
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API