GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
395 advisories
Filter by severity
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience...
High
Unreviewed
CVE-2025-34139
was published
Jul 25, 2025
The Ubia camera ecosystem fails to adequately secure API credentials,
potentially enabling an...
High
Unreviewed
CVE-2025-12636
was published
Nov 7, 2025
Argo Workflow may expose artifact repository credentials
High
CVE-2025-62157
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation...
High
Unreviewed
CVE-2025-0498
was published
Jan 30, 2025
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation...
High
Unreviewed
CVE-2025-0497
was published
Jan 30, 2025
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords...
High
Unreviewed
CVE-2024-36460
was published
Aug 12, 2024
In freeradius, the EAP-PWD function compute_password_element() leaks information about the...
High
Unreviewed
CVE-2022-41859
was published
Jan 17, 2023
Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication...
High
Unreviewed
CVE-2025-54808
was published
Oct 23, 2025
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2...
High
Unreviewed
CVE-2014-1812
was published
May 14, 2022
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an...
High
Unreviewed
CVE-2020-29583
was published
May 24, 2022
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker...
High
Unreviewed
CVE-2021-40655
was published
May 24, 2022
E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read...
High
Unreviewed
CVE-2025-52545
was published
Oct 1, 2025
All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials...
High
Unreviewed
CVE-2025-10880
was published
Sep 25, 2025
All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials...
High
Unreviewed
CVE-2025-10879
was published
Sep 25, 2025
A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web...
High
Unreviewed
CVE-2025-34078
was published
Jul 2, 2025
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a...
High
Unreviewed
CVE-2025-23342
was published
Sep 9, 2025
When a user logs in via SAP Business One native client, the SLD backend service fails to enforce...
High
Unreviewed
CVE-2025-42933
was published
Sep 9, 2025
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller...
High
Unreviewed
CVE-2025-41682
was published
Sep 8, 2025
An information disclosure vulnerability exists in the Vault API functionality of ClearML...
High
Unreviewed
CVE-2024-43779
was published
Feb 6, 2025
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm...
High
Unreviewed
CVE-2025-33093
was published
May 7, 2025
Insufficiently Protected Credentials vulnerability in ABB Aspect.This issue affects Aspect:...
High
Unreviewed
CVE-2025-53188
was published
Aug 11, 2025
Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected...
High
Unreviewed
CVE-2025-38739
was published
Aug 4, 2025
tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment
High
CVE-2024-49364
was published
for
tiny-secp256k1
(npm)
Jun 30, 2025
CyberData 011209 Intercom
does not properly store or protect web server admin credentials.
High
Unreviewed
CVE-2025-30183
was published
Jun 10, 2025
Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary...
High
Unreviewed
CVE-2021-43978
was published
Dec 9, 2021
ProTip!
Advisories are also available from the
GraphQL API