GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
640 advisories
Filter by severity
iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface,...
Moderate
Unreviewed
CVE-2018-20008
was published
May 24, 2022
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with...
Moderate
Unreviewed
CVE-2018-2028
was published
May 24, 2022
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2019-5810
was published
May 24, 2022
Jenkins Port Allocator Plugin stores credentials in plain text
Moderate
CVE-2019-10350
was published
for
org.jenkins-ci.plugins:port-allocator
(Maven)
May 24, 2022
Jenkins Gogs Plugin stored credentials in plain text
Moderate
CVE-2019-10348
was published
for
org.jenkins-ci.plugins:gogs-webhook
(Maven)
May 24, 2022
Jenkins Caliper CI Plugin stores credentials in plain text
Moderate
CVE-2019-10351
was published
for
com.brianfromoregon:caliper-ci
(Maven)
May 24, 2022
TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure...
Critical
Unreviewed
CVE-2019-13096
was published
May 24, 2022
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior...
Moderate
Unreviewed
CVE-2019-3753
was published
May 24, 2022
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it...
Moderate
Unreviewed
CVE-2019-15947
was published
May 24, 2022
DingTalk Plugin stores credentials in plain text
Low
CVE-2019-10433
was published
for
io.jenkins.plugins:dingding-notifications
(Maven)
May 24, 2022
Centreon Sensitive Data Exposure
Moderate
CVE-2019-17106
was published
for
centreon/centreon
(Composer)
May 24, 2022
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in...
High
Unreviewed
CVE-2019-15023
was published
May 24, 2022
Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell...
High
Unreviewed
CVE-2019-3767
was published
May 24, 2022
Cleartext Storage of Sensitive Information in Jenkins Extensive Testing Plugin
High
CVE-2019-10448
was published
for
jenkins.xtc:extensivetesting
(Maven)
May 24, 2022
Jenkins Sofy.AI Plugin stores API token in plain text
Moderate
CVE-2019-10447
was published
for
io.jenkins.plugins:sofy-ai
(Maven)
May 24, 2022
Jenkins iceScrum Plugin stores credentials in Cleartext
High
CVE-2019-10443
was published
for
org.jenkins-ci.plugins:icescrum
(Maven)
May 24, 2022
Jenkins NeoLoad Plugin stores credentials in cleartext
High
CVE-2019-10440
was published
for
org.jenkins-ci.plugins:neoload-jenkins-plugin
(Maven)
May 24, 2022
Jenkins View26 Test-Reporting Plugin stores access token in plain text
Moderate
CVE-2019-10452
was published
for
org.jenkins-ci.plugins:view26
(Maven)
May 24, 2022
Jenkins SOASTA CloudTest Plugin stores API token in plain text
Moderate
CVE-2019-10451
was published
for
com.soasta.jenkins:cloudtest
(Maven)
May 24, 2022
Cleartext Storage of Sensitive Information in Jenkins ElasticBox CI Plugin
Low
CVE-2019-10450
was published
for
com.elasticbox.jenkins-ci.plugins:elasticbox
(Maven)
May 24, 2022
Jenkins Fortify on Demand Plugin stores credentials in plain text
Moderate
CVE-2019-10449
was published
for
org.jenkins-ci.plugins:fortify-on-demand-uploader
(Maven)
May 24, 2022
Jenkins Delphix Plugin vulnerable to Cleartext credential storage
High
CVE-2019-10453
was published
for
org.jenkins-ci.plugins:delphix
(Maven)
May 24, 2022
Magento 2 Community Edition Weak Cryptography
Moderate
CVE-2019-8118
was published
for
magento/community-edition
(Composer)
May 24, 2022
Katello cleartext password storage issue
Low
CVE-2019-14825
was published
for
katello
(RubyGems)
May 24, 2022
An attacker with low privilege could retrieve usernames and passwords credentials from the new...
High
Unreviewed
CVE-2019-14890
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API