GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
48 advisories
Filter by severity
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext...
Moderate
Unreviewed
CVE-2025-43938
was published
Sep 10, 2025
SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in...
Moderate
Unreviewed
CVE-2025-45702
was published
Jul 24, 2025
Several credentials for the local PostgreSQL database are stored in plain text (partially base64...
Moderate
Unreviewed
CVE-2025-1709
was published
Jul 3, 2025
The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective...
Moderate
Unreviewed
CVE-2025-5760
was published
Jun 6, 2025
An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP...
Moderate
Unreviewed
CVE-2025-48046
was published
May 29, 2025
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2025-33079
was published
May 27, 2025
SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms...
Moderate
Unreviewed
CVE-2025-43005
was published
May 13, 2025
On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File...
Moderate
Unreviewed
CVE-2025-0936
was published
May 8, 2025
BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability...
Moderate
Unreviewed
CVE-2025-2770
was published
Apr 23, 2025
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive...
Moderate
Unreviewed
CVE-2024-43186
was published
Mar 29, 2025
IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local...
Moderate
Unreviewed
CVE-2024-45638
was published
Mar 14, 2025
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were...
Moderate
Unreviewed
CVE-2025-25727
was published
Feb 28, 2025
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local...
Moderate
Unreviewed
CVE-2023-50945
was published
Jan 26, 2025
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
stores user credentials in...
Moderate
Unreviewed
CVE-2024-52361
was published
Dec 18, 2024
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
could allow a privileged user to...
Moderate
Unreviewed
CVE-2023-50956
was published
Dec 18, 2024
User passwords are decrypted and stored on memory before any user logged in. Those decrypted...
Moderate
Unreviewed
CVE-2024-29978
was published
Nov 26, 2024
IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be...
Moderate
Unreviewed
CVE-2024-49351
was published
Nov 26, 2024
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to...
Moderate
Unreviewed
CVE-2024-31899
was published
Sep 26, 2024
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The...
Moderate
Unreviewed
CVE-2024-45283
was published
Sep 10, 2024
IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2024-25024
was published
Aug 15, 2024
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO!...
Moderate
Unreviewed
CVE-2024-39922
was published
Aug 13, 2024
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an...
Moderate
Unreviewed
CVE-2024-3082
was published
Jul 31, 2024
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain...
Moderate
Unreviewed
CVE-2024-39733
was published
Jul 14, 2024
BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR...
Moderate
Unreviewed
CVE-2024-39220
was published
Jul 3, 2024
IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by...
Moderate
Unreviewed
CVE-2024-25052
was published
Jun 13, 2024
ProTip!
Advisories are also available from the
GraphQL API