GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
640 advisories
Filter by severity
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world...
Moderate
Unreviewed
CVE-2011-2916
was published
Apr 22, 2022
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions...
High
Unreviewed
CVE-2009-5068
was published
Apr 21, 2022
IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a...
Moderate
Unreviewed
CVE-2021-39078
was published
Apr 20, 2022
AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to...
Moderate
Unreviewed
CVE-2022-0835
was published
Apr 12, 2022
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F...
Critical
Unreviewed
CVE-2022-25158
was published
Apr 3, 2022
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F...
Moderate
Unreviewed
CVE-2022-25160
was published
Apr 3, 2022
3CX System through 2022-03-17 stores cleartext passwords in a database.
Moderate
Unreviewed
CVE-2021-45491
was published
Mar 29, 2022
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix...
Critical
Unreviewed
CVE-2022-26148
was published
Mar 22, 2022
SnapCenter versions prior to 4.5 are susceptible to a vulnerability which could allow a local...
Moderate
Unreviewed
CVE-2022-23234
was published
Mar 17, 2022
Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows...
Moderate
Unreviewed
CVE-2022-26778
was published
Mar 11, 2022
" Insecure password storage issue.The application stores sensitive information in cleartext...
High
Unreviewed
CVE-2021-27757
was published
Mar 5, 2022
Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a...
Moderate
Unreviewed
CVE-2021-43590
was published
Mar 5, 2022
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could...
Moderate
Unreviewed
CVE-2021-35036
was published
Mar 2, 2022
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local,...
Moderate
Unreviewed
CVE-2020-14480
was published
Feb 25, 2022
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores...
High
Unreviewed
CVE-2021-3551
was published
Feb 17, 2022
NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual...
Moderate
Unreviewed
CVE-2022-21818
was published
Feb 16, 2022
Jenkins Support Core Plugin stores sensitive data in plain text
Moderate
CVE-2022-25187
was published
for
org.jenkins-ci.plugins:support-core
(Maven)
Feb 16, 2022
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS...
High
Unreviewed
CVE-2021-40363
was published
Feb 10, 2022
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct...
High
Unreviewed
CVE-2021-42642
was published
Feb 9, 2022
Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and...
High
Unreviewed
CVE-2022-22789
was published
Jan 26, 2022
Plaintext Storage of a Password vulnerability in Mitsubishi Electric MC Works64 versions 4.04E ...
Moderate
Unreviewed
CVE-2022-23129
was published
Jan 22, 2022
When the Windows Tentacle docker image starts up it logs all the commands that it runs along with...
Moderate
Unreviewed
CVE-2021-31821
was published
Jan 20, 2022
A vulnerability in the information storage architecture of several Cisco IP Phone models could...
Moderate
Unreviewed
CVE-2022-20660
was published
Jan 15, 2022
Trendnet AC2600 TEW-827DRU version 2.08B01 stores credentials in plaintext. Usernames and...
Moderate
Unreviewed
CVE-2021-20162
was published
Dec 31, 2021
Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and...
Moderate
Unreviewed
CVE-2021-20171
was published
Dec 31, 2021
ProTip!
Advisories are also available from the
GraphQL API