GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,263
Erlang
31
GitHub Actions
21
Go
2,033
Maven
5,000+
npm
3,732
NuGet
662
pip
3,411
Pub
12
RubyGems
891
Rust
865
Swift
36
Unreviewed advisories
All unreviewed
5,000+
541 advisories
Filter by severity
IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in...
Moderate
Unreviewed
CVE-2024-35117
was published
Dec 11, 2024
TP-Link TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to transmit user...
High
Unreviewed
CVE-2024-46340
was published
Dec 10, 2024
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
High
Unreviewed
CVE-2024-40582
was published
Dec 9, 2024
Oxide before 6 has unencrypted Control Plane datastores.
Moderate
Unreviewed
CVE-2024-55582
was published
Dec 9, 2024
This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a...
Moderate
Unreviewed
CVE-2024-54127
was published
Dec 5, 2024
This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in...
Moderate
Unreviewed
CVE-2024-12094
was published
Dec 5, 2024
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved...
High
Unreviewed
CVE-2024-42451
was published
Dec 4, 2024
Python package "zhmcclient" stores passwords in clear text in its HMC and API logs
Moderate
CVE-2024-53865
was published
for
zhmcclient
(pip)
Dec 2, 2024
User passwords are decrypted and stored on memory before any user logged in. Those decrypted...
Moderate
Unreviewed
CVE-2024-29146
was published
Nov 26, 2024
Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about...
Low
Unreviewed
CVE-2024-46383
was published
Nov 15, 2024
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This...
Moderate
Unreviewed
CVE-2024-11159
was published
Nov 13, 2024
Moodle has user information visibility control issues in gradebook reports
Low
CVE-2024-43429
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created...
Moderate
Unreviewed
CVE-2020-11918
was published
Nov 7, 2024
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100...
Moderate
Unreviewed
CVE-2024-34891
was published
Nov 4, 2024
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain...
Moderate
Unreviewed
CVE-2024-10523
was published
Nov 4, 2024
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information,...
Moderate
Unreviewed
CVE-2024-7783
was published
Oct 29, 2024
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in...
High
Unreviewed
CVE-2024-9991
was published
Oct 25, 2024
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test...
High
Unreviewed
CVE-2024-8070
was published
Oct 13, 2024
The health endpoint is public so everybody can see a list of all services. It is potentially...
Critical
Unreviewed
CVE-2024-9798
was published
Oct 10, 2024
The conformance validation endpoint is public so everybody can verify the conformance of...
Moderate
Unreviewed
CVE-2024-9802
was published
Oct 10, 2024
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition...
High
Unreviewed
CVE-2024-9466
was published
Oct 9, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Moderate
CVE-2024-47529
was published
for
@openc3/tool-common
(RubyGems)
Oct 2, 2024
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco...
Moderate
Unreviewed
CVE-2024-20448
was published
Oct 2, 2024
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive...
High
Unreviewed
CVE-2024-25661
was published
Oct 1, 2024
Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19...
Moderate
Unreviewed
CVE-2024-25658
was published
Oct 1, 2024
ProTip!
Advisories are also available from the
GraphQL API