GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
45 advisories
Filter by severity
Sametime is impacted by sensitive information passed in URL.
Low
Unreviewed
CVE-2023-45716
was published
Feb 10, 2024
Free5gc v3.2.1 is vulnerable to Information disclosure.
Low
Unreviewed
CVE-2022-38870
was published
Oct 25, 2022
Sensitive information accessible by physical probing of JTAG interface for some Intel(R)...
Low
Unreviewed
CVE-2022-0005
was published
May 13, 2022
IBM InfoSphere Information Server 11.7 DataStage Flow Designer
transmits sensitive information...
Low
Unreviewed
CVE-2025-25046
was published
Apr 24, 2025
A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3...
Low
Unreviewed
CVE-2025-3329
was published
Apr 7, 2025
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. ...
Low
Unreviewed
CVE-2024-42181
was published
Jan 13, 2025
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive...
Low
Unreviewed
CVE-2024-11946
was published
Dec 30, 2024
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote...
Low
Unreviewed
CVE-2024-49820
was published
Dec 17, 2024
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information...
Low
Unreviewed
CVE-2024-47577
was published
Dec 10, 2024
Moodle authorization headers preserved between "emulated redirects"
Low
CVE-2024-43432
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
A bug in query analysis of certain complex self-referential $lookup subpipelines may result in...
Low
Unreviewed
CVE-2024-8013
was published
Oct 28, 2024
The goTenna pro series does not encrypt the callsigns of its users. These callsigns reveal...
Low
Unreviewed
CVE-2024-47124
was published
Sep 26, 2024
The goTenna Pro ATAK Plugin does not encrypt the callsigns of its users.
These callsigns reveal...
Low
Unreviewed
CVE-2024-45838
was published
Sep 26, 2024
[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`
Low
CVE-2024-41124
was published
for
puncia
(pip)
Jul 19, 2024
An insecure connection between Systems Manager and CQI Reporter application could expose infusion...
Low
Unreviewed
CVE-2023-30565
was published
Jul 13, 2023
Jenkins Aqua Security Serverless Scanner Plugin showed plain text password in job configuration form fields
Low
CVE-2019-10397
was published
for
org.jenkins-ci.plugins:aqua-serverless
(Maven)
May 24, 2022
make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command...
Low
Unreviewed
CVE-2007-5626
was published
May 1, 2022
Jenkins S3 Publisher Plugin transmits credentials in plain text during configuration
Low
CVE-2020-2114
was published
for
org.jenkins-ci.plugins:s3
(Maven)
May 24, 2022
Jenkins Email Extension Plugin SMTP password transmitted and displayed in plain text
Low
CVE-2020-2232
was published
for
org.jenkins-ci.plugins:email-ext
(Maven)
May 24, 2022
Credentials transmitted in plain text by Jenkins Logstash Plugin
Low
CVE-2020-2143
was published
for
org.jenkins-ci.plugins:logstash
(Maven)
May 24, 2022
Credentials transmitted in plain text by Backlog Plugin
Low
CVE-2020-2153
was published
for
org.jenkins-ci.plugins:backlog
(Maven)
May 24, 2022
Jenkins Inedo ProGet Plugin Plugin has Cleartext Transmission of Sensitive Information
Low
CVE-2019-10412
was published
for
com.inedo.proget:inedo-proget
(Maven)
May 24, 2022
Cleartext Storage of Sensitive Information in Jenkins Build Notifications Plugin
Low
CVE-2022-34801
was published
for
tools.devnull:build-notifications
(Maven)
Jul 1, 2022
A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the...
Low
Unreviewed
CVE-2023-43503
was published
Nov 14, 2023
A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the...
Low
Unreviewed
CVE-2023-5035
was published
Nov 2, 2023
ProTip!
Advisories are also available from the
GraphQL API