GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
1,009 advisories
Filter by severity
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and...
Critical
Unreviewed
CVE-2018-19078
was published
May 13, 2022
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+...
Critical
Unreviewed
CVE-2018-18754
was published
May 13, 2022
Samsung SCX-6545X V2.00.03.01 03-23-2012 devices allows remote attackers to discover cleartext...
Critical
Unreviewed
CVE-2018-17969
was published
May 13, 2022
Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and...
Critical
Unreviewed
CVE-2018-17613
was published
May 13, 2022
Squash TM through 1.18.0 presents the cleartext passwords of external services in the...
High
Unreviewed
CVE-2018-16987
was published
May 13, 2022
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and...
Critical
Unreviewed
CVE-2018-16791
was published
May 13, 2022
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in...
Critical
Unreviewed
CVE-2018-16669
was published
May 13, 2022
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm...
Moderate
Unreviewed
CVE-2018-16222
was published
May 13, 2022
Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the...
Critical
Unreviewed
CVE-2018-16223
was published
May 13, 2022
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone...
Critical
Unreviewed
CVE-2018-14081
was published
May 13, 2022
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in...
High
Unreviewed
CVE-2018-1377
was published
May 13, 2022
Cloudtoken Insufficiently Protects Credentials
Low
CVE-2018-13390
was published
for
cloudtoken
(pip)
May 13, 2022
Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC...
High
Unreviewed
CVE-2018-13014
was published
May 13, 2022
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted...
Moderate
Unreviewed
CVE-2018-12383
was published
May 13, 2022
An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in...
Moderate
Unreviewed
CVE-2018-12260
was published
May 13, 2022
Previous releases of the Puppet device_manager module creates configuration files containing...
High
Unreviewed
CVE-2018-11748
was published
May 13, 2022
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin...
High
Unreviewed
CVE-2018-11639
was published
May 13, 2022
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3...
High
Unreviewed
CVE-2018-11634
was published
May 13, 2022
Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.
High
Unreviewed
CVE-2018-10814
was published
May 13, 2022
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow...
High
Unreviewed
CVE-2018-10355
was published
May 13, 2022
PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding,...
High
Unreviewed
CVE-2018-10327
was published
May 13, 2022
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS...
High
Unreviewed
CVE-2018-10286
was published
May 13, 2022
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in...
Critical
Unreviewed
CVE-2018-10024
was published
May 13, 2022
Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by...
Critical
Unreviewed
CVE-2018-1000627
was published
May 13, 2022
Jenkins Configuration as Code Plugin has Insufficiently Protected Credentials
High
CVE-2018-1000610
was published
for
io.jenkins:configuration-as-code
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API