GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
529 advisories
Filter by severity
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2...
Moderate
Unreviewed
CVE-2025-63361
was published
Dec 4, 2025
EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability,...
Moderate
Unreviewed
CVE-2025-13163
was published
Nov 17, 2025
EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability,...
Moderate
Unreviewed
CVE-2025-13164
was published
Nov 17, 2025
A 3rd-party component exposed its password in process arguments, allowing for low-privileged...
Moderate
Unreviewed
CVE-2025-6571
was published
Nov 11, 2025
Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD),...
Moderate
Unreviewed
CVE-2025-42897
was published
Nov 11, 2025
This vulnerability allows an attacker to access parts of the application that are not protected...
Moderate
Unreviewed
CVE-2025-12461
was published
Oct 29, 2025
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could...
Moderate
Unreviewed
CVE-2024-42192
was published
Oct 16, 2025
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike...
Moderate
Unreviewed
CVE-2025-37728
was published
Oct 7, 2025
The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it...
Moderate
Unreviewed
CVE-2025-27231
was published
Oct 3, 2025
In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content...
Moderate
Unreviewed
CVE-2025-10360
was published
Sep 24, 2025
NeuVector process with sensitive arguments lead to leakage
Moderate
CVE-2025-54467
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3)....
Moderate
Unreviewed
CVE-2025-40751
was published
Aug 12, 2025
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has...
Moderate
Unreviewed
CVE-2025-54394
was published
Aug 7, 2025
Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC"...
Moderate
Unreviewed
CVE-2025-5922
was published
Jul 29, 2025
Opencast still publishes global system account credentials
Moderate
CVE-2025-54380
was published
for
org.opencastproject:opencast-common
(Maven)
Jul 25, 2025
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22....
Moderate
Unreviewed
CVE-2025-7565
was published
Jul 14, 2025
Jenkins Applitools Eyes Plugin vulnerability does not mask API keys on its job configuration form
Moderate
CVE-2025-53743
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Jenkins ReadyAPI Functional Testing Plugin vulnerability exposes secrets
Moderate
CVE-2025-53657
was published
for
org.jenkins-ci.plugins:soapui-pro-functional-testing
(Maven)
Jul 9, 2025
Jenkins IFTTT Build Notifier Plugin vulnerability exposes IFTTT Maker Channel Keys
Moderate
CVE-2025-53662
was published
for
org.jenkins-ci.plugins:ifttt-build-notifier
(Maven)
Jul 9, 2025
Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
Moderate
CVE-2025-53665
was published
for
com.apica:ApicaLoadtest
(Maven)
Jul 9, 2025
Jenkins QMetry Test Management Plugin vulnerability exposes API keys
Moderate
CVE-2025-53660
was published
for
org.jenkins-ci.plugins:qmetry-test-management
(Maven)
Jul 9, 2025
Jenkins ReadyAPI Functional Testing Plugin vulnerability stores unencrypted authentication credentials
Moderate
CVE-2025-53656
was published
for
org.jenkins-ci.plugins:soapui-pro-functional-testing
(Maven)
Jul 9, 2025
Jenkins IBM Cloud DevOps Plugin vulnerability exposes SonarQube authentication tokens
Moderate
CVE-2025-53663
was published
for
com.ibm.devops:ibm-cloud-devops
(Maven)
Jul 9, 2025
Jenkins Dead Man's Snitch Plugin vulnerability stores tokens in plain text
Moderate
CVE-2025-53666
was published
for
org.jenkins-ci.plugins:deadmanssnitch
(Maven)
Jul 9, 2025
Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
Moderate
CVE-2025-53664
was published
for
com.apica:ApicaLoadtest
(Maven)
Jul 9, 2025
ProTip!
Advisories are also available from the
GraphQL API