GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,233
Erlang
31
GitHub Actions
20
Go
1,992
Maven
5,000+
npm
3,709
NuGet
661
pip
3,346
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
527 advisories
Filter by severity
LOYTEC electronics GmbH LINX Configurator 7.4.10 is vulnerable to Insecure Permissions. Cleartext...
High
Unreviewed
CVE-2023-46384
was published
Dec 1, 2023
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from...
Moderate
Unreviewed
CVE-2024-39732
was published
Jul 14, 2024
Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc....
High
Unreviewed
CVE-2024-6921
was published
Sep 2, 2024
django-nopassword stores secrets in cleartext
High
CVE-2019-10682
was published
for
django-nopassword
(pip)
Jun 5, 2020
User passwords are stored in clear text in the Django session
Moderate
CVE-2020-15105
was published
for
django-two-factor-auth
(pip)
Jul 10, 2020
Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If...
High
Unreviewed
CVE-2024-41716
was published
Sep 4, 2024
django-celery-results Stores Sensitive Information In Cleartext
High
CVE-2020-17495
was published
for
django-celery-results
(pip)
Jun 4, 2021
An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to...
Moderate
Unreviewed
CVE-2024-41629
was published
Sep 12, 2024
Tina search token leak via lock file in TinaCMS
High
CVE-2024-45391
was published
for
@tinacms/cli
(npm)
Sep 3, 2024
A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the...
Moderate
Unreviewed
CVE-2024-8689
was published
Sep 11, 2024
Apache Airflow logs passwords in plaintext
Low
CVE-2020-17511
was published
for
apache-airflow
(pip)
Dec 17, 2020
An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext...
High
Unreviewed
CVE-2019-16638
was published
Jul 16, 2024
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a...
Moderate
Unreviewed
CVE-2024-33892
was published
Aug 2, 2024
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive...
High
Unreviewed
CVE-2024-24375
was published
Mar 7, 2024
IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2024-25024
was published
Aug 15, 2024
A vulnerability identified in storing and reusing information in Advance Authentication. This...
High
Unreviewed
CVE-2021-22509
was published
Aug 28, 2024
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011,...
High
Unreviewed
CVE-2023-49341
was published
Mar 9, 2024
Mattermost doesn't redact remote users' original email addresses
Moderate
CVE-2024-32939
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Aug 22, 2024
An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local...
Moderate
Unreviewed
CVE-2024-5916
was published
Aug 14, 2024
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
High
Unreviewed
CVE-2024-36790
was published
Jun 7, 2024
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b...
Moderate
Unreviewed
CVE-2024-29954
was published
Jun 26, 2024
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA...
Moderate
Unreviewed
CVE-2024-41689
was published
Jul 26, 2024
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing...
High
Unreviewed
CVE-2024-41688
was published
Jul 26, 2024
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default...
High
Unreviewed
CVE-2024-41690
was published
Jul 26, 2024
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials...
High
Unreviewed
CVE-2024-41691
was published
Jul 26, 2024
ProTip!
Advisories are also available from the
GraphQL API