GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,047
Maven
5,000+
npm
3,739
NuGet
663
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
189 advisories
Filter by severity
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of...
High
Unreviewed
CVE-2023-51740
was published
Jan 17, 2024
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of...
High
Unreviewed
CVE-2023-51741
was published
Jan 17, 2024
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x...
High
Unreviewed
CVE-2023-28616
was published
Dec 26, 2023
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718),...
High
Unreviewed
CVE-2023-31300
was published
Dec 29, 2023
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length...
High
Unreviewed
CVE-2017-7252
was published
Nov 3, 2023
Keycloak vulnerable to Plaintext Storage of User Password
High
CVE-2023-4918
was published
for
org.keycloak:keycloak-core
(Maven)
Sep 12, 2023
The Android Client application, when enrolled with the define method 1 (the user manually...
High
Unreviewed
CVE-2023-45321
was published
Oct 25, 2023
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were...
High
Unreviewed
CVE-2019-10102
was published
May 24, 2022
Pgsync Contains Cleartext Transmission of Sensitive Information
High
CVE-2021-31671
was published
for
pgsync
(RubyGems)
Apr 27, 2021
The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which...
High
Unreviewed
CVE-2022-2083
was published
Sep 6, 2022
Gitops Run insecure communication
High
CVE-2022-23509
was published
for
github.com/weaveworks/weave-gitops
(Go)
Jan 9, 2023
phpMyFAQ has insecure HTTP cookies
High
CVE-2022-4409
was published
for
thorsten/phpmyfaq
(Composer)
Dec 11, 2022
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain...
High
Unreviewed
CVE-2021-20409
was published
May 24, 2022
In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials...
High
Unreviewed
CVE-2023-1802
was published
Apr 6, 2023
Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java...
High
Unreviewed
CVE-2023-1656
was published
Mar 29, 2023
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which...
High
Unreviewed
CVE-2019-13498
was published
May 24, 2022
LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in...
High
Unreviewed
CVE-2023-22806
was published
Feb 15, 2023
A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS...
High
Unreviewed
CVE-2022-40693
was published
Feb 7, 2023
Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application...
High
Unreviewed
CVE-2022-45546
was published
Feb 15, 2023
Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive...
High
Unreviewed
CVE-2023-25016
was published
Feb 6, 2023
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict...
High
Unreviewed
CVE-2019-4162
was published
May 24, 2022
An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext...
High
Unreviewed
CVE-2021-40846
was published
Mar 5, 2022
Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar...
High
Unreviewed
CVE-2021-29397
was published
Feb 9, 2022
Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore,...
High
Unreviewed
CVE-2021-41835
was published
Jan 22, 2022
Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the...
High
Unreviewed
CVE-2021-20175
was published
Dec 31, 2021
ProTip!
Advisories are also available from the
GraphQL API