GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,233
Erlang
31
GitHub Actions
20
Go
1,992
Maven
5,000+
npm
3,709
NuGet
661
pip
3,346
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
300 advisories
Filter by severity
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs...
Moderate
Unreviewed
CVE-2021-3585
was published
Aug 27, 2022
The affected device stores sensitive information in cleartext, which may allow an authenticated...
Moderate
Unreviewed
CVE-2022-2569
was published
Aug 25, 2022
Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A...
Moderate
Unreviewed
CVE-2022-29090
was published
Aug 11, 2022
HCL Launch may store certain data for recurring activities in a plain text format.
Moderate
Unreviewed
CVE-2022-27549
was published
Jul 7, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in...
Moderate
Unreviewed
CVE-2022-22366
was published
Jul 2, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive...
Moderate
Unreviewed
CVE-2022-22367
was published
Jul 2, 2022
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text...
Moderate
Unreviewed
CVE-2022-22478
was published
Jul 1, 2022
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
Moderate
Unreviewed
CVE-2021-41639
was published
Jun 25, 2022
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as...
Moderate
Unreviewed
CVE-2017-20040
was published
Jun 12, 2022
** DISPUTED ** FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH...
Moderate
Unreviewed
CVE-2022-29620
was published
Jun 8, 2022
E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND...
Moderate
Unreviewed
CVE-2022-23236
was published
Jun 3, 2022
UltraLog Express device management software stores user’s information in cleartext. Any user can...
Moderate
Unreviewed
CVE-2020-3921
was published
May 24, 2022
During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor...
Moderate
Unreviewed
CVE-2020-9045
was published
May 24, 2022
Secom Co. Dr.ID, a Door Access Control and Personnel Attendance Management system, stores users’...
Moderate
Unreviewed
CVE-2020-3935
was published
May 24, 2022
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in...
Moderate
Unreviewed
CVE-2019-4314
was published
May 24, 2022
Jenkins NeuVector Vulnerability Scanner Plugin stored credentials in plain text
Moderate
CVE-2019-10430
was published
for
io.jenkins.plugins:neuvector-vulnerability-scanner
(Maven)
May 24, 2022
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which...
Moderate
Unreviewed
CVE-2021-38949
was published
May 24, 2022
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The...
Moderate
Unreviewed
CVE-2020-10053
was published
May 24, 2022
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov...
Moderate
Unreviewed
CVE-2021-25502
was published
May 24, 2022
A cleartext storage of sensitive information in GUI in FortiADC versions 5.4.3 and below, 6.0.0...
Moderate
Unreviewed
CVE-2020-15935
was published
May 24, 2022
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below...
Moderate
Unreviewed
CVE-2021-41023
was published
May 24, 2022
IBM Jazz Team Server products stores user credentials in clear text which can be read by an...
Moderate
Unreviewed
CVE-2021-29786
was published
May 24, 2022
IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can...
Moderate
Unreviewed
CVE-2021-38911
was published
May 24, 2022
Rich Text Edit Control Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2021-40454
was published
May 24, 2022
IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an...
Moderate
Unreviewed
CVE-2021-38915
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API