GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
640 advisories
Filter by severity
The hard drives of the device are not encrypted using a full volume encryption feature such as...
High
Unreviewed
CVE-2025-27460
was published
Jul 3, 2025
junit-platform-reporting can leak Git credentials through its OpenTestReportGeneratingListener
Moderate
CVE-2025-53103
was published
for
org.junit.platform:junit-platform-reporting
(Maven)
Jul 1, 2025
juju/utils leaks private key in certs
Moderate
CVE-2025-6224
was published
for
github.com/juju/utils/v4/cert
(Go)
Jul 1, 2025
Credentials are not cleared from memory after being used. A user with Administrator permissions...
Moderate
Unreviewed
CVE-2024-24915
was published
Jun 29, 2025
The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with...
Moderate
Unreviewed
CVE-2023-28912
was published
Jun 28, 2025
A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on...
Low
Unreviewed
CVE-2025-6748
was published
Jun 27, 2025
Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.
Low
Unreviewed
CVE-2025-47820
was published
Jun 27, 2025
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage...
Low
Unreviewed
CVE-2025-47824
was published
Jun 27, 2025
A local, low-privileged attacker can learn the password of the connected controller in PLC...
Moderate
Unreviewed
CVE-2025-41647
was published
Jun 26, 2025
Successful exploitation of the vulnerability could allow an attacker to intercept data and...
Low
Unreviewed
CVE-2025-48463
was published
Jun 26, 2025
react-native-keys insecurely stores encryption cipher and Base64 chunks
High
CVE-2025-45001
was published
for
react-native-keys
(npm)
Jun 9, 2025
IBM InfoSphere Information Server 11.7 stores credential information for database authentication...
Moderate
Unreviewed
CVE-2025-1499
was published
Jun 1, 2025
Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including...
High
Unreviewed
CVE-2025-44614
was published
May 30, 2025
Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A...
Moderate
Unreviewed
CVE-2025-32752
was published
May 29, 2025
Mautic does not shield .env files from web traffic
Moderate
CVE-2024-47056
was published
for
mautic/core
(Composer)
May 28, 2025
The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access...
Moderate
Unreviewed
CVE-2025-4053
was published
May 26, 2025
A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on...
Moderate
Unreviewed
CVE-2025-5154
was published
May 25, 2025
The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext...
Moderate
Unreviewed
CVE-2024-56428
was published
May 21, 2025
Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant)...
Moderate
Unreviewed
CVE-2025-4737
was published
May 15, 2025
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic....
Low
Unreviewed
CVE-2025-4537
was published
May 11, 2025
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro...
High
Unreviewed
CVE-2025-46634
was published
May 2, 2025
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro...
High
Unreviewed
CVE-2025-46633
was published
May 2, 2025
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information...
High
Unreviewed
CVE-2025-3395
was published
Apr 30, 2025
A vulnerability in the “Backup & Restore” functionality of the web application of ctrlX OS allows...
Moderate
Unreviewed
CVE-2025-27532
was published
Apr 30, 2025
BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability...
Moderate
Unreviewed
CVE-2025-2770
was published
Apr 23, 2025
ProTip!
Advisories are also available from the
GraphQL API