GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
21
Go
2,003
Maven
5,000+
npm
3,714
NuGet
661
pip
3,387
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,050 advisories
Filter by severity
Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key....
Moderate
Unreviewed
CVE-2022-45424
was published
Dec 27, 2022
IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear...
Moderate
Unreviewed
CVE-2022-22458
was published
Dec 23, 2022
A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension...
Moderate
Unreviewed
CVE-2022-4612
was published
Dec 19, 2022
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical...
Moderate
Unreviewed
CVE-2022-46142
was published
Dec 13, 2022
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through...
Moderate
Unreviewed
CVE-2022-4312
was published
Dec 12, 2022
HCL Launch could allow a user with administrative privileges, including "Manage Security"...
Moderate
Unreviewed
CVE-2022-42445
was published
Dec 12, 2022
Insufficiently Protected Credentials vulnerability in the remote backups application on Western...
Moderate
Unreviewed
CVE-2022-29839
was published
Dec 9, 2022
Craft CMS discloses password hashes
High
CVE-2022-37783
was published
for
craftcms/cms
(Composer)
Dec 5, 2022
Plaintext storage of a password vulnerability exists in +F FS040U software versions v2.3.4 and...
Moderate
Unreviewed
CVE-2022-43442
was published
Dec 5, 2022
IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a...
Moderate
Unreviewed
CVE-2022-41732
was published
Nov 28, 2022
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3...
Moderate
Unreviewed
CVE-2022-29833
was published
Nov 25, 2022
Apache Dolphin Scheduler has insufficiently protected credentials
High
CVE-2022-26885
was published
for
org.apache.dolphinscheduler:dolphinscheduler-common
(Maven)
Nov 24, 2022
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated...
Critical
Unreviewed
CVE-2022-45276
was published
Nov 23, 2022
Plaintext storage of password after a reset in org.xwiki.platform:xwiki-platform-security-authentication-default
Moderate
CVE-2022-41933
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-default
(Maven)
Nov 21, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7...
Moderate
Unreviewed
CVE-2022-40751
was published
Nov 17, 2022
Plaintext Storage of a Password in Jenkins NS-ND Integration Performance Publisher Plugin
Moderate
CVE-2022-45392
was published
for
io.jenkins.plugins:cavisson-ns-nd-integration
(Maven)
Nov 16, 2022
Jenkins Reverse Proxy Auth Plugin vulnerable due to plaintext storage of passwords
Moderate
CVE-2022-45384
was published
for
org.jenkins-ci.main:reverse-proxy-auth-plugin
(Maven)
Nov 16, 2022
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is...
Critical
Unreviewed
CVE-2022-37109
was published
Nov 15, 2022
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0...
Moderate
Unreviewed
CVE-2022-42132
was published
Nov 15, 2022
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure...
Moderate
Unreviewed
CVE-2022-40845
was published
Nov 15, 2022
Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1,...
High
Unreviewed
CVE-2022-26341
was published
Nov 11, 2022
Exfiltration of hashed SMB credentials on Windows via file:// redirect
Moderate
CVE-2022-36077
was published
for
electron
(npm)
Nov 10, 2022
Dashlane password and Keepass Server password in My Account Settings are not encrypted in the...
Moderate
Unreviewed
CVE-2022-3781
was published
Nov 2, 2022
Plaintext storage of tokens in pulp_ansible
Moderate
CVE-2022-3644
was published
for
pulp-ansible
(pip)
Oct 25, 2022
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3...
High
Unreviewed
CVE-2022-41575
was published
Oct 21, 2022
ProTip!
Advisories are also available from the
GraphQL API