GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,744
Maven
5,000+
npm
4,341
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
192 advisories
Filter by severity
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3...
Critical
Unreviewed
CVE-2017-7913
was published
May 13, 2022
On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File...
Moderate
Unreviewed
CVE-2025-0936
was published
May 8, 2025
AWS secrets displayed without masking by Jenkins S3 Explorer Plugin
Low
CVE-2022-43426
was published
for
io.jenkins.plugins:s3explorer
(Maven)
Oct 19, 2022
SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms...
Moderate
Unreviewed
CVE-2025-43005
was published
May 13, 2025
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated...
Moderate
Unreviewed
CVE-2022-3287
was published
Sep 29, 2022
A vulnerability exists in the SOAP Web services of the Asset
Suite versions listed below. If...
Critical
Unreviewed
CVE-2025-2500
was published
May 30, 2025
The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective...
Moderate
Unreviewed
CVE-2025-5760
was published
Jun 6, 2025
Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information...
Critical
Unreviewed
CVE-2025-5893
was published
Jun 9, 2025
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2025-33079
was published
May 27, 2025
Multiple wireless router models from Sapido have an Exposure of Sensitive Information...
Critical
Unreviewed
CVE-2025-6560
was published
Jun 26, 2025
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of...
Critical
Unreviewed
CVE-2025-6561
was published
Jun 26, 2025
Several credentials for the local PostgreSQL database are stored in plain text (partially base64...
Moderate
Unreviewed
CVE-2025-1709
was published
Jul 3, 2025
LITEON IC48A firmware versions prior to 01.00.19r and LITEON IC80A firmware versions prior to 01...
High
Unreviewed
CVE-2025-7357
was published
Jul 16, 2025
Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.
High
Unreviewed
CVE-2025-52164
was published
Jul 18, 2025
SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in...
Moderate
Unreviewed
CVE-2025-45702
was published
Jul 24, 2025
BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability...
Moderate
Unreviewed
CVE-2025-2770
was published
Apr 23, 2025
An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP...
Moderate
Unreviewed
CVE-2025-48046
was published
May 29, 2025
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext...
Moderate
Unreviewed
CVE-2025-43938
was published
Sep 10, 2025
WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to...
High
Unreviewed
CVE-2025-3758
was published
May 8, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments)...
Critical
Unreviewed
CVE-2025-34210
was published
Oct 2, 2025
In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns...
Moderate
Unreviewed
CVE-2024-9418
was published
Mar 20, 2025
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6...
Moderate
Unreviewed
CVE-2025-36002
was published
Oct 16, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014...
Critical
Unreviewed
CVE-2025-27656
was published
Mar 5, 2025
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive...
Moderate
Unreviewed
CVE-2023-31002
was published
Feb 7, 2024
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords...
High
Unreviewed
CVE-2024-36460
was published
Aug 12, 2024
ProTip!
Advisories are also available from the
GraphQL API