GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,047
Maven
5,000+
npm
3,739
NuGet
666
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
238 advisories
Filter by severity
An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP...
Moderate
Unreviewed
CVE-2023-35833
was published
Jul 13, 2023
ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without...
Moderate
Unreviewed
CVE-2023-31195
was published
Jun 13, 2023
A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS...
Moderate
Unreviewed
CVE-2022-41327
was published
Jun 13, 2023
IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information...
Moderate
Unreviewed
CVE-2023-27861
was published
Jun 5, 2023
Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A),...
Moderate
Unreviewed
CVE-2023-0864
was published
May 17, 2023
Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2...
Moderate
Unreviewed
CVE-2023-25070
was published
May 10, 2023
Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows...
Moderate
Unreviewed
CVE-2023-29680
was published
May 2, 2023
Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an...
Moderate
Unreviewed
CVE-2023-29681
was published
May 2, 2023
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0...
Moderate
Unreviewed
CVE-2019-14942
was published
Apr 16, 2023
The Samba AD DC administration tool, when operating against a remote LDAP server, will by default...
Moderate
Unreviewed
CVE-2023-0922
was published
Apr 4, 2023
An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6...
Moderate
Unreviewed
CVE-2023-1648
was published
Mar 28, 2023
An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password...
Moderate
Unreviewed
CVE-2023-27927
was published
Mar 27, 2023
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear...
Moderate
Unreviewed
CVE-2022-38458
was published
Mar 21, 2023
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that...
Moderate
Unreviewed
CVE-2023-23915
was published
Feb 23, 2023
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows...
Moderate
Unreviewed
CVE-2023-0001
was published
Feb 8, 2023
Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being...
Moderate
Unreviewed
CVE-2023-23130
was published
Feb 1, 2023
IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when...
Moderate
Unreviewed
CVE-2023-22863
was published
Jan 18, 2023
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version...
Moderate
Unreviewed
CVE-2023-22597
was published
Jan 13, 2023
IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to...
Moderate
Unreviewed
CVE-2020-4497
was published
Dec 15, 2022
The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is...
Moderate
Unreviewed
CVE-2020-9420
was published
Dec 14, 2022
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer...
Moderate
Unreviewed
CVE-2022-45877
was published
Dec 8, 2022
In certain Secustation products the administrator account password can be read. This affects V2.5...
Moderate
Unreviewed
CVE-2022-40939
was published
Dec 8, 2022
Telepad allows an attacker (in a man-in-the-middle position between the server and a connected...
Moderate
Unreviewed
CVE-2022-45478
was published
Dec 5, 2022
PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the...
Moderate
Unreviewed
CVE-2022-45480
was published
Dec 2, 2022
Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected...
Moderate
Unreviewed
CVE-2022-45483
was published
Dec 2, 2022
ProTip!
Advisories are also available from the
GraphQL API