GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,670
Maven
5,000+
npm
4,296
NuGet
760
pip
4,075
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
656 advisories
Filter by severity
FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless...
Moderate
Unreviewed
CVE-2025-25613
was published
Nov 20, 2025
An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6...
High
Unreviewed
CVE-2025-63208
was published
Nov 19, 2025
Liferay Portal Stores Password Reset Tokens in Plain Text
Moderate
CVE-2025-62261
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 28, 2025
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11...
Low
Unreviewed
CVE-2025-54342
was published
Nov 14, 2025
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import...
Moderate
Unreviewed
CVE-2025-34270
was published
Oct 31, 2025
Jenkins Applitools Eyes Plugin vulnerability exposes unencrypted keys to certain authenticated users
Moderate
CVE-2025-53742
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Jenkins Kryptowire Plugin vulnerability stores unencrypted Kryptowire API key
Moderate
CVE-2025-53672
was published
for
io.jenkins.plugins:kryptowire
(Maven)
Jul 9, 2025
Jenkins Nouvola DiveCloud Plugin vulnerability stores unencrypted credentials
Moderate
CVE-2025-53670
was published
for
org.jenkins-ci.plugins:nouvola-divecloud
(Maven)
Jul 9, 2025
LOYTEC electronics GmbH LINX Configurator 7.4.10 is vulnerable to Insecure Permissions. Cleartext...
High
Unreviewed
CVE-2023-46384
was published
Dec 1, 2023
The Kiuwan Local Analyzer (KLA) Java scanning application contains several
hard-coded secrets in...
High
Unreviewed
CVE-2023-49113
was published
Jun 20, 2024
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created...
Moderate
Unreviewed
CVE-2020-11918
was published
Nov 7, 2024
User passwords are decrypted and stored on memory before any user logged in. Those decrypted...
Moderate
Unreviewed
CVE-2024-29146
was published
Nov 26, 2024
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a...
Moderate
Unreviewed
CVE-2024-33892
was published
Aug 2, 2024
A vulnerability has been identified in Omnivise T3000 Application Server (All versions), Omnivise...
High
Unreviewed
CVE-2024-38877
was published
Aug 2, 2024
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive...
Moderate
Unreviewed
CVE-2023-31002
was published
Feb 7, 2024
Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4...
Moderate
Unreviewed
CVE-2023-22332
was published
Jan 30, 2023
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330...
High
Unreviewed
CVE-2025-27685
was published
Mar 5, 2025
A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected...
Moderate
Unreviewed
CVE-2024-31486
was published
May 14, 2024
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local...
High
Unreviewed
CVE-2025-21061
was published
Oct 10, 2025
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local...
Moderate
Unreviewed
CVE-2025-21060
was published
Oct 10, 2025
Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.
Low
Unreviewed
CVE-2025-47820
was published
Jun 27, 2025
Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could...
Moderate
Unreviewed
CVE-2025-48428
was published
Oct 23, 2025
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to...
Moderate
Unreviewed
CVE-2011-4723
was published
May 17, 2022
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an...
High
Unreviewed
CVE-2020-29583
was published
May 24, 2022
Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2025-55334
was published
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API