GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,233
Erlang
31
GitHub Actions
20
Go
1,992
Maven
5,000+
npm
3,709
NuGet
661
pip
3,346
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
300 advisories
Filter by severity
On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server...
Moderate
Unreviewed
CVE-2022-45897
was published
Jan 31, 2023
A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the...
Moderate
Unreviewed
CVE-2020-10706
was published
May 24, 2022
Plaintext Storage of a Password in Jenkins TestQuality Updater Plugin
Moderate
CVE-2023-24454
was published
for
org.jenkins-ci.plugins:testquality-updater
(Maven)
Jan 26, 2023
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where...
Moderate
Unreviewed
CVE-2019-14886
was published
May 24, 2022
Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4...
Moderate
Unreviewed
CVE-2023-22332
was published
Jan 30, 2023
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information...
Moderate
Unreviewed
CVE-2022-45098
was published
Feb 1, 2023
IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information...
Moderate
Unreviewed
CVE-2023-24964
was published
Feb 17, 2023
A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux...
Moderate
Unreviewed
CVE-2022-45154
was published
Feb 15, 2023
Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with...
Moderate
Unreviewed
CVE-2022-24410
was published
Feb 10, 2023
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with...
Moderate
Unreviewed
CVE-2018-2028
was published
May 24, 2022
MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.
Moderate
Unreviewed
CVE-2022-31405
was published
Feb 27, 2023
Apache Linkis vulnerable to Exposure of Sensitive Information
Moderate
CVE-2022-44644
was published
for
org.apache.linkis:linkis
(Maven)
Jan 31, 2023
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a...
Moderate
Unreviewed
CVE-2022-34910
was published
Feb 27, 2023
An information disclosure vulnerability allows sensitive key material to be included in technical...
Moderate
Unreviewed
CVE-2022-48310
was published
Mar 1, 2023
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA...
Moderate
Unreviewed
CVE-2023-20059
was published
Mar 23, 2023
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with...
Moderate
Unreviewed
CVE-2023-25596
was published
Mar 22, 2023
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the...
Moderate
Unreviewed
CVE-2023-25263
was published
Mar 27, 2023
Jenkins Consul KV Builder Plugin stores HashiCorp Consul ACL Token unencrypted
Moderate
CVE-2023-30530
was published
for
org.jenkins-ci.plugins:consul-kv-builder
(Maven)
Apr 12, 2023
Jenkins Consul KV Builder Plugin stores HashiCorp Consul ACL Token unencrypted
Moderate
CVE-2023-30531
was published
for
org.jenkins-ci.plugins:consul-kv-builder
(Maven)
Apr 12, 2023
Jenkins Report Portal Plugin allows users with Item/Extended Read permission to view tokens on Jenkins controller
Moderate
CVE-2023-30523
was published
for
org.jenkins-ci.plugins:reportportal
(Maven)
Apr 12, 2023
D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via...
Moderate
Unreviewed
CVE-2019-15656
was published
May 24, 2022
Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric...
Moderate
Unreviewed
CVE-2022-29832
was published
Nov 25, 2022
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through...
Moderate
Unreviewed
CVE-2022-4312
was published
Dec 12, 2022
Plaintext storage of password after a reset in org.xwiki.platform:xwiki-platform-security-authentication-default
Moderate
CVE-2022-41933
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-default
(Maven)
Nov 21, 2022
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only...
Moderate
Unreviewed
CVE-2022-26390
was published
Sep 10, 2022
ProTip!
Advisories are also available from the
GraphQL API