GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,035
Maven
5,000+
npm
3,732
NuGet
662
pip
3,413
Pub
12
RubyGems
891
Rust
865
Swift
36
Unreviewed advisories
All unreviewed
5,000+
310 advisories
Filter by severity
Certain General Electric Renewable Energy products store cleartext credentials in flash memory....
Moderate
Unreviewed
CVE-2022-24120
was published
Dec 26, 2022
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
Moderate
Unreviewed
CVE-2020-15325
was published
Sep 30, 2022
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including...
Moderate
Unreviewed
CVE-2022-22457
was published
Dec 23, 2022
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it...
Moderate
Unreviewed
CVE-2019-15947
was published
May 24, 2022
iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface,...
Moderate
Unreviewed
CVE-2018-20008
was published
May 24, 2022
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in...
Moderate
Unreviewed
CVE-2019-4314
was published
May 24, 2022
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain...
Moderate
Unreviewed
CVE-2022-22484
was published
May 18, 2022
Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An...
Moderate
Unreviewed
CVE-2022-33918
was published
Oct 13, 2022
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which...
Moderate
Unreviewed
CVE-2021-39009
was published
Sep 2, 2022
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read...
Moderate
Unreviewed
CVE-2022-22470
was published
Jan 9, 2023
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre...
Moderate
Unreviewed
CVE-2021-23211
was published
May 24, 2022
The affected device stores sensitive information in cleartext, which may allow an authenticated...
Moderate
Unreviewed
CVE-2022-2569
was published
Aug 25, 2022
Sensitive information was stored in plain text in a file that is accessible by a user with a...
Moderate
Unreviewed
CVE-2022-47512
was published
Dec 19, 2022
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
Moderate
Unreviewed
CVE-2021-41639
was published
Jun 25, 2022
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text...
Moderate
Unreviewed
CVE-2022-22478
was published
Jul 1, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in...
Moderate
Unreviewed
CVE-2022-22366
was published
Jul 2, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive...
Moderate
Unreviewed
CVE-2022-22367
was published
Jul 2, 2022
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as...
Moderate
Unreviewed
CVE-2017-20040
was published
Jun 12, 2022
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of...
Moderate
Unreviewed
CVE-2021-36165
was published
May 24, 2022
IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access...
Moderate
Unreviewed
CVE-2022-41740
was published
Jan 5, 2023
** DISPUTED ** FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH...
Moderate
Unreviewed
CVE-2022-29620
was published
Jun 8, 2022
During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor...
Moderate
Unreviewed
CVE-2020-9045
was published
May 24, 2022
A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions <...
Moderate
Unreviewed
CVE-2021-33716
was published
May 24, 2022
Shopware contains sensitive data in backend customer module
Moderate
CVE-2022-36101
was published
for
shopware/shopware
(Composer)
Sep 16, 2022
E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND...
Moderate
Unreviewed
CVE-2022-23236
was published
Jun 3, 2022
ProTip!
Advisories are also available from the
GraphQL API