GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,086
Maven
5,000+
npm
3,749
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
548 advisories
Filter by severity
In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP...
Moderate
Unreviewed
CVE-2020-5867
was published
May 24, 2022
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres...
Moderate
Unreviewed
CVE-2020-5865
was published
May 24, 2022
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak...
Moderate
Unreviewed
CVE-2020-7488
was published
May 24, 2022
The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon...
Low
Unreviewed
CVE-2019-19107
was published
May 24, 2022
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on...
Moderate
Unreviewed
CVE-2020-7483
was published
May 24, 2022
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext...
Moderate
Unreviewed
CVE-2020-6195
was published
May 24, 2022
Passwords transmitted in plain text by Jenkins Artifactory Plugin
Low
CVE-2020-2165
was published
for
org.jenkins-ci.plugins:artifactory
(Maven)
May 24, 2022
NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access...
Moderate
Unreviewed
CVE-2019-16067
was published
May 24, 2022
Credentials transmitted in plain text by Skytap Cloud CI Plugin
Low
CVE-2020-2157
was published
for
org.jenkins-ci.plugins:skytap
(Maven)
May 24, 2022
Credentials transmitted in plain text by Jenkins DeployHub Plugin
Low
CVE-2020-2156
was published
for
com.openmake:deployhub
(Maven)
May 24, 2022
Credentials transmitted in plain text by Backlog Plugin
Low
CVE-2020-2153
was published
for
org.jenkins-ci.plugins:backlog
(Maven)
May 24, 2022
Credentials transmitted in plain text by OpenShift Deployer Plugin
Low
CVE-2020-2155
was published
for
org.jenkins-ci.plugins:openshift-deployer
(Maven)
May 24, 2022
Jenkins Quality Gates Plugin transmits credentials in plain text during configuration
Low
CVE-2020-2151
was published
for
org.jenkins-ci.plugins:quality-gates
(Maven)
May 24, 2022
Jenkins Sonar Quality Gates Plugin transmits credentials in plain text during configuration
Low
CVE-2020-2150
was published
for
org.jenkins-ci.plugins:sonar-quality-gates
(Maven)
May 24, 2022
Credentials transmitted in plain text by Repository Connector Plugin
Low
CVE-2020-2149
was published
for
org.jenkins-ci.plugins:repository-connector
(Maven)
May 24, 2022
Credentials transmitted in plain text by Jenkins Logstash Plugin
Low
CVE-2020-2143
was published
for
org.jenkins-ci.plugins:logstash
(Maven)
May 24, 2022
Missing permission checks in Jenkins P4 Plugin
Moderate
CVE-2020-2142
was published
for
org.jenkins-ci.plugins:p4
(Maven)
May 24, 2022
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900...
Moderate
Unreviewed
CVE-2019-18863
was published
May 24, 2022
Jenkins S3 Publisher Plugin transmits credentials in plain text during configuration
Low
CVE-2020-2114
was published
for
org.jenkins-ci.plugins:s3
(Maven)
May 24, 2022
The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.
Moderate
Unreviewed
CVE-2020-8506
was published
May 24, 2022
The Citytv Video application 4.08.0 for Android and 3.35 for iOS sends Unencrypted Analytics.
Moderate
Unreviewed
CVE-2020-8507
was published
May 24, 2022
The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6...
High
Unreviewed
CVE-2019-19967
was published
May 24, 2022
Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer...
Moderate
Unreviewed
CVE-2019-8632
was published
May 24, 2022
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin...
Moderate
Unreviewed
CVE-2019-19890
was published
May 24, 2022
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The...
Moderate
Unreviewed
CVE-2019-19889
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API