GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
177 advisories
Filter by severity
Navidrome Stores JWT Secret in Plaintext in navidrome.db
High
CVE-2024-56362
was published
for
github.com/navidrome/navidrome
(Go)
Dec 23, 2024
GoPhish sends cleartext passwords
High
CVE-2024-55196
was published
for
github.com/gophish/gophish
(Go)
Dec 19, 2024
An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the...
High
Unreviewed
CVE-2024-51175
was published
Dec 18, 2024
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
High
Unreviewed
CVE-2024-40582
was published
Dec 9, 2024
TP-Link TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to transmit user...
High
Unreviewed
CVE-2024-46340
was published
Dec 10, 2024
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved...
High
Unreviewed
CVE-2024-42451
was published
Dec 4, 2024
Grafana information disclosure
High
CVE-2020-12458
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to...
High
Unreviewed
CVE-2024-28327
was published
Apr 26, 2024
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in...
High
Unreviewed
CVE-2024-9991
was published
Oct 25, 2024
Sensitive data written to disk unencrypted in Spark
High
CVE-2019-10099
was published
for
org.apache.spark:spark-core_2.11
(Maven)
Aug 8, 2019
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition...
High
Unreviewed
CVE-2024-9466
was published
Oct 9, 2024
The Danfoss AK-EM100 stores login credentials in cleartext.
High
Unreviewed
CVE-2023-22584
was published
Jun 11, 2023
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test...
High
Unreviewed
CVE-2024-8070
was published
Oct 13, 2024
Nautobot vulnerable to exposure of hashed user passwords via REST API
High
CVE-2023-46128
was published
for
nautobot
(pip)
Oct 24, 2023
An unauthorized user is able to gain access to sensitive data, including credentials, by...
High
Unreviewed
CVE-2024-38280
was published
Jun 13, 2024
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive...
High
Unreviewed
CVE-2024-25661
was published
Oct 1, 2024
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in...
High
Unreviewed
CVE-2024-28809
was published
Sep 30, 2024
Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may...
High
Unreviewed
CVE-2024-45862
was published
Sep 19, 2024
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within...
High
Unreviewed
CVE-2024-8459
was published
Sep 30, 2024
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of...
High
Unreviewed
CVE-2023-6874
was published
Feb 5, 2024
IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform...
High
Unreviewed
CVE-2023-50957
was published
Feb 10, 2024
LOYTEC electronics GmbH LINX-212 6.2.4 and LINX-151 7.2.4 are vulnerable to Insecure Permissions...
High
Unreviewed
CVE-2023-46388
was published
Dec 1, 2023
LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 firmware 7.2.4 are vulnerable to...
High
Unreviewed
CVE-2023-46386
was published
Dec 1, 2023
LOYTEC electronics GmbH LINX Configurator 7.4.10 is vulnerable to Insecure Permissions. Cleartext...
High
Unreviewed
CVE-2023-46384
was published
Dec 1, 2023
Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc....
High
Unreviewed
CVE-2024-6921
was published
Sep 2, 2024
ProTip!
Advisories are also available from the
GraphQL API