GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
640 advisories
Filter by severity
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as...
Moderate
Unreviewed
CVE-2017-20040
was published
Jun 12, 2022
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4...
High
Unreviewed
CVE-2021-45025
was published
Jun 18, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive...
Moderate
Unreviewed
CVE-2022-22367
was published
Jul 2, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in...
Moderate
Unreviewed
CVE-2022-22366
was published
Jul 2, 2022
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text...
Moderate
Unreviewed
CVE-2022-22478
was published
Jul 1, 2022
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
Moderate
Unreviewed
CVE-2021-41639
was published
Jun 25, 2022
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away...
High
Unreviewed
CVE-2020-8225
was published
May 24, 2022
Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access...
High
Unreviewed
CVE-2022-30626
was published
Jul 19, 2022
The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed...
High
Unreviewed
CVE-2022-24660
was published
Jul 21, 2022
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an...
High
Unreviewed
CVE-2022-34924
was published
Aug 3, 2022
Sensitive information was stored in plain text in a file that is accessible by a user with a...
Moderate
Unreviewed
CVE-2022-47512
was published
Dec 19, 2022
The affected device stores sensitive information in cleartext, which may allow an authenticated...
Moderate
Unreviewed
CVE-2022-2569
was published
Aug 25, 2022
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre...
Moderate
Unreviewed
CVE-2021-23211
was published
May 24, 2022
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read...
Moderate
Unreviewed
CVE-2022-22470
was published
Jan 9, 2023
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which...
Moderate
Unreviewed
CVE-2021-39009
was published
Sep 2, 2022
Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An...
Moderate
Unreviewed
CVE-2022-33918
was published
Oct 13, 2022
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain...
Moderate
Unreviewed
CVE-2022-22484
was published
May 18, 2022
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in...
Moderate
Unreviewed
CVE-2019-4314
was published
May 24, 2022
iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface,...
Moderate
Unreviewed
CVE-2018-20008
was published
May 24, 2022
A vulnerability, which was classified as problematic, was found in SourceCodester Guest...
High
Unreviewed
CVE-2022-2813
was published
Aug 16, 2022
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it...
Moderate
Unreviewed
CVE-2019-15947
was published
May 24, 2022
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including...
Moderate
Unreviewed
CVE-2022-22457
was published
Dec 23, 2022
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
Moderate
Unreviewed
CVE-2020-15325
was published
Sep 30, 2022
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
Critical
Unreviewed
CVE-2020-15332
was published
Sep 30, 2022
Certain General Electric Renewable Energy products store cleartext credentials in flash memory....
Moderate
Unreviewed
CVE-2022-24120
was published
Dec 26, 2022
ProTip!
Advisories are also available from the
GraphQL API