GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
518 advisories
Filter by severity
nsufficiently Protected Credentials in ActiveMQ Artemis
Moderate
CVE-2020-10727
was published
for
org.apache.activemq:artemis-commons
(Maven)
May 24, 2022
1Password SCIM Bridge before 1.6.2 mishandles validation of requests for log files.
Moderate
Unreviewed
CVE-2021-26905
was published
May 24, 2022
SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for...
Moderate
Unreviewed
CVE-2021-21448
was published
May 24, 2022
Plaintext Storage of a Password in Jenkins Eagle Tester Plugin
Moderate
CVE-2020-2129
was published
for
com.mobileenerlytics.eagle.tester:eagle-tester
(Maven)
May 24, 2022
Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets,...
Moderate
Unreviewed
CVE-2021-3130
was published
May 24, 2022
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an...
Moderate
Unreviewed
CVE-2021-1589
was published
May 24, 2022
A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when...
Moderate
Unreviewed
CVE-2020-27831
was published
May 24, 2022
A malicious actor having access to the exported configuration file may obtain the stored...
Moderate
Unreviewed
CVE-2022-27179
was published
Apr 21, 2022
IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a...
Moderate
Unreviewed
CVE-2022-41732
was published
Nov 28, 2022
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in...
Moderate
Unreviewed
CVE-2021-3681
was published
Apr 19, 2022
IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain...
Moderate
Unreviewed
CVE-2021-39026
was published
Feb 19, 2022
Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An...
Moderate
Unreviewed
CVE-2022-22550
was published
Apr 13, 2022
Private key stored in plain text by Jenkins Google Compute Engine Plugin
Moderate
CVE-2022-29052
was published
for
org.jenkins-ci.plugins:google-compute-engine
(Maven)
Apr 13, 2022
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
Moderate
Unreviewed
CVE-2022-28651
was published
Apr 6, 2022
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a...
Moderate
Unreviewed
CVE-2021-45892
was published
Apr 6, 2022
McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to...
Moderate
Unreviewed
CVE-2022-0859
was published
Mar 24, 2022
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a...
Moderate
Unreviewed
CVE-2020-25184
was published
Mar 19, 2022
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who...
Moderate
Unreviewed
CVE-2022-34837
was published
Aug 25, 2022
ProTip!
Advisories are also available from the
GraphQL API