GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,177 advisories
Filter by severity
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a...
High
Unreviewed
CVE-2025-23342
was published
Sep 9, 2025
When a user logs in via SAP Business One native client, the SLD backend service fails to enforce...
High
Unreviewed
CVE-2025-42933
was published
Sep 9, 2025
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller...
High
Unreviewed
CVE-2025-41682
was published
Sep 8, 2025
An information disclosure vulnerability exists in the Vault API functionality of ClearML...
High
Unreviewed
CVE-2024-43779
was published
Feb 6, 2025
NeuVector process with sensitive arguments lead to leakage
Moderate
CVE-2025-54467
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
Opencast still publishes global system account credentials
Moderate
CVE-2025-54380
was published
for
org.opencastproject:opencast-common
(Maven)
Jul 25, 2025
An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the...
Critical
Unreviewed
CVE-2025-52095
was published
Aug 22, 2025
The Eaton Foreseer software provides the feasibility for the user to configure external servers...
Moderate
Unreviewed
CVE-2024-31415
was published
Sep 13, 2024
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm...
High
Unreviewed
CVE-2025-33093
was published
May 7, 2025
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure...
Moderate
Unreviewed
CVE-2025-3480
was published
May 22, 2025
Jenkins Mattermost Notification Plugin contains unencrypted storage of secret token
Moderate
CVE-2019-10459
was published
for
org.jenkins-ci.plugins:mattermost
(Maven)
May 24, 2022
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3)....
Moderate
Unreviewed
CVE-2025-40751
was published
Aug 12, 2025
Insufficiently Protected Credentials vulnerability in ABB Aspect.This issue affects Aspect:...
High
Unreviewed
CVE-2025-53188
was published
Aug 11, 2025
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has...
Moderate
Unreviewed
CVE-2025-54394
was published
Aug 7, 2025
Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected...
High
Unreviewed
CVE-2025-38739
was published
Aug 4, 2025
Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC"...
Moderate
Unreviewed
CVE-2025-5922
was published
Jul 29, 2025
Mattermost has Insufficiently Protected Credentials
Low
CVE-2025-6227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messages
Moderate
CVE-2025-53650
was published
for
org.jenkins-ci.plugins:credentials-binding
(Maven)
Jul 9, 2025
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22....
Moderate
Unreviewed
CVE-2025-7565
was published
Jul 14, 2025
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
Moderate
CVE-2022-42132
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
Moderate
CVE-2025-53664
was published
for
com.apica:ApicaLoadtest
(Maven)
Jul 9, 2025
Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
Moderate
CVE-2025-53665
was published
for
com.apica:ApicaLoadtest
(Maven)
Jul 9, 2025
Jenkins IBM Cloud DevOps Plugin vulnerability exposes SonarQube authentication tokens
Moderate
CVE-2025-53663
was published
for
com.ibm.devops:ibm-cloud-devops
(Maven)
Jul 9, 2025
Jenkins IFTTT Build Notifier Plugin vulnerability exposes IFTTT Maker Channel Keys
Moderate
CVE-2025-53662
was published
for
org.jenkins-ci.plugins:ifttt-build-notifier
(Maven)
Jul 9, 2025
Jenkins QMetry Test Management Plugin vulnerability exposes API keys
Moderate
CVE-2025-53660
was published
for
org.jenkins-ci.plugins:qmetry-test-management
(Maven)
Jul 9, 2025
ProTip!
Advisories are also available from the
GraphQL API