GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,499
Maven
5,000+
npm
4,138
NuGet
735
pip
3,945
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
640 advisories
Filter by severity
In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information...
Moderate
Unreviewed
CVE-2024-28065
was published
Apr 5, 2024
The NMAP Importer service may expose data store credentials to authorized users of the Windows...
Moderate
Unreviewed
CVE-2024-23584
was published
Apr 9, 2024
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to...
Moderate
Unreviewed
CVE-2024-29952
was published
Apr 18, 2024
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in...
Moderate
Unreviewed
CVE-2024-29956
was published
Apr 18, 2024
Sentry vulnerable to leaking superuser cleartext password in logs
High
CVE-2024-32474
was published
for
sentry
(pip)
Apr 18, 2024
Electrolink transmitters store credentials in clear-text. Use of these credentials could allow...
High
Unreviewed
CVE-2024-3742
was published
Apr 19, 2024
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information...
Low
Unreviewed
CVE-2023-37396
was published
Apr 19, 2024
A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This...
Low
Unreviewed
CVE-2024-4235
was published
Apr 26, 2024
Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to...
High
Unreviewed
CVE-2024-28327
was published
Apr 26, 2024
An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted...
Low
Unreviewed
CVE-2023-46294
was published
May 1, 2024
NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This...
Moderate
Unreviewed
CVE-2023-27370
was published
May 3, 2024
An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and...
Moderate
Unreviewed
CVE-2024-4840
was published
May 14, 2024
A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected...
Moderate
Unreviewed
CVE-2024-31486
was published
May 14, 2024
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords...
Moderate
Unreviewed
CVE-2024-31840
was published
May 21, 2024
Password confirmation stored in plain text via registration form in statamic/cms
Low
CVE-2024-36119
was published
for
statamic/cms
(Composer)
Jun 2, 2024
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
High
Unreviewed
CVE-2024-36790
was published
Jun 7, 2024
A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is
stored in...
Low
Unreviewed
CVE-2024-28024
was published
Jun 11, 2024
An unauthorized user is able to gain access to sensitive data, including credentials, by...
High
Unreviewed
CVE-2024-38280
was published
Jun 13, 2024
An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and...
Moderate
Unreviewed
CVE-2024-36589
was published
Jun 13, 2024
The Kiuwan Local Analyzer (KLA) Java scanning application contains several
hard-coded secrets in...
High
Unreviewed
CVE-2023-49113
was published
Jun 20, 2024
The decrypted configuration file contains the password in cleartext
which is used to configure...
Critical
Unreviewed
CVE-2024-36497
was published
Jun 24, 2024
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b...
Moderate
Unreviewed
CVE-2024-29954
was published
Jun 26, 2024
NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it...
Low
Unreviewed
CVE-2024-39846
was published
Jun 29, 2024
The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores...
Low
Unreviewed
CVE-2024-40594
was published
Jul 6, 2024
Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi...
Moderate
Unreviewed
CVE-2024-40750
was published
Jul 9, 2024
ProTip!
Advisories are also available from the
GraphQL API