GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
518 advisories
Filter by severity
Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS
Moderate
CVE-2025-32963
was published
for
github.com/minio/operator
(Go)
Apr 21, 2025
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure...
Moderate
Unreviewed
CVE-2025-2772
was published
Apr 23, 2025
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may...
Moderate
Unreviewed
CVE-2022-30944
was published
Aug 19, 2022
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid...
Moderate
Unreviewed
CVE-2024-20282
was published
Apr 3, 2024
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure...
Moderate
Unreviewed
CVE-2022-40845
was published
Nov 15, 2022
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys,...
Moderate
Unreviewed
CVE-2024-42172
was published
Jan 11, 2025
A passback vulnerability which relates to production printers and office multifunction printers.
Moderate
Unreviewed
CVE-2025-3078
was published
May 20, 2025
A passback vulnerability which relates to office/small office multifunction printers and laser...
Moderate
Unreviewed
CVE-2025-3079
was published
May 20, 2025
All versions of the Medtronic 2090 Carelink Programmer are affected by a per-product username and...
Moderate
Unreviewed
CVE-2018-5446
was published
May 13, 2022
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access...
Moderate
Unreviewed
CVE-2025-2394
was published
May 23, 2025
Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password
Moderate
CVE-2021-29043
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine...
Moderate
Unreviewed
CVE-2020-8422
was published
May 24, 2022
An issue was discovered in Keeper Password Manager for Desktop version 16.10.2, and the...
Moderate
Unreviewed
CVE-2023-36266
was published
Jul 12, 2023
Requests vulnerable to .netrc credentials leak via malicious URLs
Moderate
CVE-2024-47081
was published
for
requests
(pip)
Jun 9, 2025
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2025-33079
was published
May 27, 2025
An authenticated attacker can reconfigure the target device to use an external service (such as...
Moderate
Unreviewed
CVE-2024-51984
was published
Jun 26, 2025
Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers...
Moderate
Unreviewed
CVE-2025-6081
was published
Jul 1, 2025
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers...
Moderate
Unreviewed
CVE-2025-4679
was published
May 16, 2025
Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage
Moderate
Unreviewed
CVE-2025-24508
was published
Jul 7, 2025
Jenkins Statistics Gatherer Plugin vulnerability exposes AWS Secret Key
Moderate
CVE-2025-53654
was published
for
org.jenkins.plugins.statistics.gatherer:statistics-gatherer
(Maven)
Jul 9, 2025
Jenkins ReadyAPI Functional Testing Plugin vulnerability exposes secrets
Moderate
CVE-2025-53657
was published
for
org.jenkins-ci.plugins:soapui-pro-functional-testing
(Maven)
Jul 9, 2025
Jenkins Dead Man's Snitch Plugin vulnerability does not mask tokens
Moderate
CVE-2025-53667
was published
for
org.jenkins-ci.plugins:deadmanssnitch
(Maven)
Jul 9, 2025
Jenkins Dead Man's Snitch Plugin vulnerability stores tokens in plain text
Moderate
CVE-2025-53666
was published
for
org.jenkins-ci.plugins:deadmanssnitch
(Maven)
Jul 9, 2025
Jenkins Applitools Eyes Plugin vulnerability does not mask API keys on its job configuration form
Moderate
CVE-2025-53743
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
ProTip!
Advisories are also available from the
GraphQL API