GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,178 advisories
Filter by severity
Jenkins Statistics Gatherer Plugin vulnerability exposes AWS Secret Key
Moderate
CVE-2025-53654
was published
for
org.jenkins.plugins.statistics.gatherer:statistics-gatherer
(Maven)
Jul 9, 2025
Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messages
Moderate
CVE-2025-53650
was published
for
org.jenkins-ci.plugins:credentials-binding
(Maven)
Jul 9, 2025
Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage
Moderate
Unreviewed
CVE-2025-24508
was published
Jul 7, 2025
A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web...
High
Unreviewed
CVE-2025-34078
was published
Jul 2, 2025
Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers...
Moderate
Unreviewed
CVE-2025-6081
was published
Jul 1, 2025
tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment
High
CVE-2024-49364
was published
for
tiny-secp256k1
(npm)
Jun 30, 2025
An authenticated attacker can reconfigure the target device to use an external service (such as...
Moderate
Unreviewed
CVE-2024-51984
was published
Jun 26, 2025
A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611...
Low
Unreviewed
CVE-2025-6526
was published
Jun 26, 2025
CyberData 011209 Intercom
does not properly store or protect web server admin credentials.
High
Unreviewed
CVE-2025-30183
was published
Jun 10, 2025
Requests vulnerable to .netrc credentials leak via malicious URLs
Moderate
CVE-2024-47081
was published
for
requests
(pip)
Jun 9, 2025
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2025-33079
was published
May 27, 2025
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access...
Moderate
Unreviewed
CVE-2025-2394
was published
May 23, 2025
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure...
Moderate
Unreviewed
CVE-2025-3480
was published
May 22, 2025
A passback vulnerability which relates to office/small office multifunction printers and laser...
Moderate
Unreviewed
CVE-2025-3079
was published
May 20, 2025
A passback vulnerability which relates to production printers and office multifunction printers.
Moderate
Unreviewed
CVE-2025-3078
was published
May 20, 2025
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers...
Moderate
Unreviewed
CVE-2025-4679
was published
May 16, 2025
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm...
High
Unreviewed
CVE-2025-33093
was published
May 7, 2025
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure...
Moderate
Unreviewed
CVE-2025-2772
was published
Apr 23, 2025
Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS
Moderate
CVE-2025-32963
was published
for
github.com/minio/operator
(Go)
Apr 21, 2025
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01...
High
Unreviewed
CVE-2025-28228
was published
Apr 21, 2025
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password...
Critical
Unreviewed
CVE-2025-22372
was published
Apr 14, 2025
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are...
Low
Unreviewed
CVE-2025-27192
was published
Apr 8, 2025
Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to...
High
Unreviewed
CVE-2025-26628
was published
Apr 8, 2025
The exposure of credentials in the call forwarding configuration module in MeetMe products in...
High
Unreviewed
CVE-2025-2908
was published
Mar 28, 2025
ProTip!
Advisories are also available from the
GraphQL API