GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,700
Maven
5,000+
npm
4,327
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
178 advisories
Filter by severity
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments...
Critical
Unreviewed
CVE-2025-36096
was published
Nov 14, 2025
In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure...
Critical
Unreviewed
CVE-2025-64689
was published
Nov 10, 2025
Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly...
Critical
Unreviewed
CVE-2025-54863
was published
Nov 4, 2025
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily...
Critical
Unreviewed
CVE-2025-6519
was published
Oct 10, 2025
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each...
Critical
Unreviewed
CVE-2025-52549
was published
Oct 1, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and...
Critical
Unreviewed
CVE-2025-34196
was published
Sep 29, 2025
An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the...
Critical
Unreviewed
CVE-2025-52095
was published
Aug 22, 2025
The Sante PACS Server Web Portal sends credential information without encryption.
Critical
Unreviewed
CVE-2025-54156
was published
Aug 19, 2025
m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected Credentials
Critical
GHSA-x6gv-2rvh-qmp6
was published
for
BoldestDungeon/steam-workshop-deploy
(GitHub Actions)
Aug 13, 2025
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password...
Critical
Unreviewed
CVE-2025-22372
was published
Apr 14, 2025
An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605...
Critical
Unreviewed
CVE-2025-25650
was published
Mar 17, 2025
Insufficiently Protected Credentials
vulnerability in OpenText Identity Manager Advanced Edition...
Critical
Unreviewed
CVE-2024-12799
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014...
Critical
Unreviewed
CVE-2025-27650
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253...
Critical
Unreviewed
CVE-2025-27648
was published
Mar 5, 2025
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded...
Critical
Unreviewed
CVE-2025-25570
was published
Feb 28, 2025
The standard user uses the run as function to start the MEAC applications with administrative...
Critical
Unreviewed
CVE-2025-0867
was published
Feb 14, 2025
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation...
Critical
Unreviewed
CVE-2025-0477
was published
Jan 30, 2025
Password Vulnerability in Safety production process management system v1.0 allows a remote...
Critical
Unreviewed
CVE-2024-57395
was published
Jan 30, 2025
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.
Critical
Unreviewed
CVE-2024-40583
was published
Dec 9, 2024
STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware...
Critical
Unreviewed
CVE-2023-48010
was published
Dec 5, 2024
Username Enumeration vulnerabilities allow access to application level username add, delete,...
Critical
Unreviewed
CVE-2024-51545
was published
Dec 5, 2024
Missing Authentication for Critical Function vulnerability in OpenText™ AccuRev for LDAP...
Critical
Unreviewed
CVE-2019-17082
was published
Nov 26, 2024
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required...
Critical
Unreviewed
CVE-2024-11703
was published
Nov 26, 2024
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache...
Critical
Unreviewed
CVE-2024-44000
was published
Oct 20, 2024
Grafana plugin SDK Information Leakage
Critical
CVE-2024-8986
was published
for
github.com/grafana/grafana-plugin-sdk-go
(Go)
Sep 19, 2024
ProTip!
Advisories are also available from the
GraphQL API