GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,132
Erlang
29
GitHub Actions
19
Go
1,937
Maven
5,000+
npm
3,676
NuGet
642
pip
3,292
Pub
11
RubyGems
877
Rust
830
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
31 advisories
Filter by severity
An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain...
High
Unreviewed
CVE-2024-48770
was published
Oct 11, 2024
An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a...
High
Unreviewed
CVE-2024-22808
was published
Apr 22, 2024
An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when...
High
Unreviewed
CVE-2024-29968
was published
Apr 19, 2024
This issue was addressed through improved state management. This issue is fixed in macOS Sonoma...
High
Unreviewed
CVE-2023-42913
was published
Mar 28, 2024
The encrypted subject of an email message could be incorrectly and permanently assigned to an...
High
Unreviewed
CVE-2024-1936
was published
Mar 5, 2024
Intelbras Roteador ACtion RF 1200 1.2.2 esposes the Password in Cookie resulting in Login Bypass.
High
Unreviewed
CVE-2024-22773
was published
Feb 6, 2024
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to...
High
Unreviewed
CVE-2023-45182
was published
Dec 14, 2023
A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows...
High
Unreviewed
CVE-2023-32184
was published
Sep 19, 2023
** UNSUPPPORTED WHEN ASSIGNED **
Sending some requests in the web application of the...
High
Unreviewed
CVE-2023-41965
was published
Sep 18, 2023
Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information...
High
Unreviewed
CVE-2023-37879
was published
Sep 15, 2023
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile...
High
Unreviewed
CVE-2023-40728
was published
Sep 14, 2023
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions...
High
Unreviewed
CVE-2022-46484
was published
Aug 2, 2023
Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate...
High
Unreviewed
CVE-2023-22687
was published
Jul 6, 2023
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may...
High
Unreviewed
CVE-2022-43475
was published
May 10, 2023
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may...
High
Unreviewed
CVE-2022-44619
was published
May 10, 2023
Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view...
High
Unreviewed
CVE-2021-36546
was published
Feb 3, 2023
Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such...
High
Unreviewed
CVE-2022-37835
was published
Sep 13, 2022
In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server...
High
Unreviewed
CVE-2022-28168
was published
Jun 28, 2022
For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6...
High
Unreviewed
CVE-2020-8481
was published
May 24, 2022
A vulnerability involving insecure storage of sensitive information has been reported to affect...
High
Unreviewed
CVE-2021-28813
was published
May 24, 2022
Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption),...
High
Unreviewed
CVE-2021-39289
was published
May 24, 2022
Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information...
High
Unreviewed
CVE-2021-22914
was published
May 24, 2022
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files ...
High
Unreviewed
CVE-2021-25276
was published
May 24, 2022
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
High
Unreviewed
CVE-2021-25776
was published
May 24, 2022
Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information...
High
Unreviewed
CVE-2020-25966
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API