GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
21
Go
2,003
Maven
5,000+
npm
3,714
NuGet
661
pip
3,387
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,051 advisories
Filter by severity
Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all...
High
Unreviewed
CVE-2022-26844
was published
Aug 19, 2022
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may...
Moderate
Unreviewed
CVE-2022-30944
was published
Aug 19, 2022
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may...
Critical
Unreviewed
CVE-2022-30601
was published
Aug 19, 2022
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering...
Moderate
Unreviewed
CVE-2022-29959
was published
Aug 17, 2022
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat...
Moderate
Unreviewed
CVE-2020-10710
was published
Aug 17, 2022
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static...
High
Unreviewed
CVE-2022-36524
was published
Aug 16, 2022
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE...
Moderate
Unreviewed
CVE-2022-20914
was published
Aug 11, 2022
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials...
Moderate
Unreviewed
CVE-2022-22983
was published
Aug 11, 2022
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible...
Critical
Unreviewed
CVE-2022-30285
was published
Aug 3, 2022
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently...
Moderate
Unreviewed
CVE-2022-33169
was published
Aug 2, 2022
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal...
Moderate
Unreviewed
CVE-2021-27785
was published
Jul 31, 2022
In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to...
High
Unreviewed
CVE-2022-31205
was published
Jul 27, 2022
BigFix Web Reports authorized users may see SMTP credentials in clear text.
Moderate
Unreviewed
CVE-2022-27544
was published
Jul 20, 2022
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices,...
High
Unreviewed
CVE-2022-28371
was published
Jul 15, 2022
Implemented protections on AWS credentials that were not properly protected.
High
Unreviewed
CVE-2022-22998
was published
Jul 13, 2022
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its...
High
Unreviewed
CVE-2022-1794
was published
Jul 12, 2022
rpc.py vulnerable to Deserialization of Untrusted Data
Critical
CVE-2022-35411
was published
for
rpc.py
(pip)
Jul 9, 2022
HCL Launch stores user credentials in plain clear text which can be read by a local user.
Moderate
Unreviewed
CVE-2022-27548
was published
Jul 7, 2022
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS...
Critical
Unreviewed
CVE-2021-41506
was published
Jul 1, 2022
Plaintext Storage of a Password in Jenkins Elasticsearch Query Plugin
Low
CVE-2022-34807
was published
for
org.jenkins-ci.plugins:elasticsearch-query
(Maven)
Jul 1, 2022
Password stored in plain text by Jenkins RQM Plugin
Low
CVE-2022-34809
was published
for
net.praqma:rqm-plugin
(Maven)
Jul 1, 2022
Plaintext Storage of a Password in Jenkins Skype notifier Plugin
Low
CVE-2022-34805
was published
for
org.jenkins-ci.plugins:skype-notifier
(Maven)
Jul 1, 2022
Plaintext Storage of a Password in Jenkins Jigomerge Plugin
Low
CVE-2022-34806
was published
for
org.jenkins-ci.plugins:jigomerge
(Maven)
Jul 1, 2022
Passwords stored in plain text by Jenkins hpe-network-virtualization plugin
Low
CVE-2022-34816
was published
for
org.jenkins-ci.plugins:hpe-network-virtualization
(Maven)
Jul 1, 2022
Token stored in plain text by Jenkins Cisco Spark Plugin
Low
CVE-2022-34808
was published
for
org.jenkins-ci.plugins:cisco-spark
(Maven)
Jul 1, 2022
ProTip!
Advisories are also available from the
GraphQL API