GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
525 advisories
Filter by severity
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created...
Moderate
Unreviewed
CVE-2020-11918
was published
Nov 7, 2024
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100...
Moderate
Unreviewed
CVE-2024-34891
was published
Nov 4, 2024
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain...
Moderate
Unreviewed
CVE-2024-10523
was published
Nov 4, 2024
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information,...
Moderate
Unreviewed
CVE-2024-7783
was published
Oct 29, 2024
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in...
High
Unreviewed
CVE-2024-9991
was published
Oct 25, 2024
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test...
High
Unreviewed
CVE-2024-8070
was published
Oct 13, 2024
The health endpoint is public so everybody can see a list of all services. It is potentially...
Critical
Unreviewed
CVE-2024-9798
was published
Oct 10, 2024
The conformance validation endpoint is public so everybody can verify the conformance of...
Moderate
Unreviewed
CVE-2024-9802
was published
Oct 10, 2024
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition...
High
Unreviewed
CVE-2024-9466
was published
Oct 9, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Moderate
CVE-2024-47529
was published
for
@openc3/tool-common
(RubyGems)
Oct 2, 2024
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco...
Moderate
Unreviewed
CVE-2024-20448
was published
Oct 2, 2024
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive...
High
Unreviewed
CVE-2024-25661
was published
Oct 1, 2024
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information...
Moderate
Unreviewed
CVE-2024-28807
was published
Sep 30, 2024
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic...
Moderate
Unreviewed
CVE-2024-28810
was published
Sep 30, 2024
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in...
High
Unreviewed
CVE-2024-28809
was published
Sep 30, 2024
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within...
High
Unreviewed
CVE-2024-8459
was published
Sep 30, 2024
Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp...
Critical
Unreviewed
CVE-2024-8644
was published
Sep 27, 2024
A flaw was found in oVirt. A user with administrator privileges, including users with the...
Moderate
Unreviewed
CVE-2024-7259
was published
Sep 26, 2024
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in...
Low
Unreviewed
CVE-2023-5359
was published
Sep 25, 2024
The configuration file stores credentials in cleartext. An attacker with local access rights can...
Moderate
Unreviewed
CVE-2024-6785
was published
Sep 21, 2024
A vulnerability, which was classified as problematic, was found in code-projects Blood Bank...
Moderate
Unreviewed
CVE-2024-9040
was published
Sep 20, 2024
Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may...
High
Unreviewed
CVE-2024-45862
was published
Sep 19, 2024
An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to...
Moderate
Unreviewed
CVE-2024-41629
was published
Sep 12, 2024
No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command...
Critical
Unreviewed
CVE-2024-40457
was published
Sep 12, 2024
A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the...
Moderate
Unreviewed
CVE-2024-8689
was published
Sep 11, 2024
ProTip!
Advisories are also available from the
GraphQL API