GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
448 advisories
Filter by severity
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be...
Moderate
Unreviewed
CVE-2018-1882
was published
May 13, 2022
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext...
High
Unreviewed
CVE-2016-0876
was published
May 13, 2022
During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions...
High
Unreviewed
CVE-2022-28214
was published
May 12, 2022
Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
Low
Unreviewed
CVE-2022-28162
was published
May 10, 2022
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass....
Moderate
Unreviewed
CVE-2022-29868
was published
May 10, 2022
SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the...
Moderate
Unreviewed
CVE-2010-0225
was published
May 2, 2022
The Huawei D100 stores the administrator's account name and password in cleartext in a cookie,...
Moderate
Unreviewed
CVE-2009-2272
was published
May 2, 2022
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish...
Low
Unreviewed
CVE-2008-1567
was published
May 1, 2022
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication,...
Moderate
Unreviewed
CVE-2008-0174
was published
May 1, 2022
Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext...
Low
Unreviewed
CVE-2005-2209
was published
May 1, 2022
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to...
Moderate
Unreviewed
CVE-2005-2160
was published
May 1, 2022
D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file,...
High
Unreviewed
CVE-2005-1828
was published
May 1, 2022
phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie,...
Moderate
Unreviewed
CVE-2002-1800
was published
Apr 30, 2022
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a...
Low
Unreviewed
CVE-2002-1696
was published
Apr 30, 2022
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for...
Moderate
Unreviewed
CVE-2001-1536
was published
Apr 30, 2022
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores...
Moderate
Unreviewed
CVE-2001-1537
was published
Apr 30, 2022
Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file,...
High
Unreviewed
CVE-2001-1481
was published
Apr 30, 2022
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1,...
Moderate
Unreviewed
CVE-2004-2397
was published
Apr 29, 2022
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and...
High
Unreviewed
CVE-2021-36460
was published
Apr 26, 2022
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world...
Moderate
Unreviewed
CVE-2011-2916
was published
Apr 22, 2022
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions...
High
Unreviewed
CVE-2009-5068
was published
Apr 21, 2022
IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a...
Moderate
Unreviewed
CVE-2021-39078
was published
Apr 20, 2022
AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to...
Moderate
Unreviewed
CVE-2022-0835
was published
Apr 12, 2022
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F...
Moderate
Unreviewed
CVE-2022-25160
was published
Apr 3, 2022
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F...
Critical
Unreviewed
CVE-2022-25158
was published
Apr 3, 2022
ProTip!
Advisories are also available from the
GraphQL API