GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,047
Maven
5,000+
npm
3,739
NuGet
665
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
189 advisories
Filter by severity
In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials...
High
Unreviewed
CVE-2023-1802
was published
Apr 6, 2023
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain...
High
Unreviewed
CVE-2021-20409
was published
May 24, 2022
phpMyFAQ has insecure HTTP cookies
High
CVE-2022-4409
was published
for
thorsten/phpmyfaq
(Composer)
Dec 11, 2022
Gitops Run insecure communication
High
CVE-2022-23509
was published
for
github.com/weaveworks/weave-gitops
(Go)
Jan 9, 2023
The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which...
High
Unreviewed
CVE-2022-2083
was published
Sep 6, 2022
Pgsync Contains Cleartext Transmission of Sensitive Information
High
CVE-2021-31671
was published
for
pgsync
(RubyGems)
Apr 27, 2021
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were...
High
Unreviewed
CVE-2019-10102
was published
May 24, 2022
The Android Client application, when enrolled with the define method 1 (the user manually...
High
Unreviewed
CVE-2023-45321
was published
Oct 25, 2023
Keycloak vulnerable to Plaintext Storage of User Password
High
CVE-2023-4918
was published
for
org.keycloak:keycloak-core
(Maven)
Sep 12, 2023
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length...
High
Unreviewed
CVE-2017-7252
was published
Nov 3, 2023
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718),...
High
Unreviewed
CVE-2023-31300
was published
Dec 29, 2023
An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x...
High
Unreviewed
CVE-2023-28616
was published
Dec 26, 2023
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of...
High
Unreviewed
CVE-2023-51740
was published
Jan 17, 2024
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of...
High
Unreviewed
CVE-2023-51741
was published
Jan 17, 2024
An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information...
High
Unreviewed
CVE-2023-50614
was published
Jan 19, 2024
Jenkins Aqua Security Scanner Plugin showed plain text password in configuration form
High
CVE-2019-10428
was published
for
org.jenkins-ci.plugins:aqua-security-scanner
(Maven)
May 24, 2022
The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext...
High
Unreviewed
CVE-2008-4390
was published
May 2, 2022
OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the...
High
Unreviewed
CVE-2008-0374
was published
May 1, 2022
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances...
High
Unreviewed
CVE-2023-32328
was published
Feb 7, 2024
Cleartext Transmission of Sensitive Information in Apache nifi
High
CVE-2018-17195
was published
for
org.apache.nifi:nifi
(Maven)
Dec 20, 2018
An unauthenticated remote attacker can influence the communication due to the lack of encryption...
High
Unreviewed
CVE-2024-26288
was published
Mar 12, 2024
The affected product is vulnerable to a cleartext transmission of sensitive information...
High
Unreviewed
CVE-2024-0860
was published
Mar 14, 2024
A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep...
High
Unreviewed
CVE-2022-43551
was published
Dec 23, 2022
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of...
High
Unreviewed
CVE-2024-25960
was published
Mar 28, 2024
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0...
High
Unreviewed
CVE-2018-1360
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API