GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
532 advisories
Filter by severity
User passwords are decrypted and stored on memory before any user logged in. Those decrypted...
Moderate
Unreviewed
CVE-2024-29146
was published
Nov 26, 2024
An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and...
Moderate
Unreviewed
CVE-2024-36589
was published
Jun 13, 2024
NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it...
Low
Unreviewed
CVE-2024-39846
was published
Jun 29, 2024
An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and...
Moderate
Unreviewed
CVE-2024-4840
was published
May 14, 2024
Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19...
Moderate
Unreviewed
CVE-2024-25658
was published
Oct 1, 2024
Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi...
Moderate
Unreviewed
CVE-2024-40750
was published
Jul 9, 2024
Infinispan caches credentials in clear text
Moderate
CVE-2023-5384
was published
for
org.infinispan:infinispan-cachestore-jdbc
(Maven)
Dec 28, 2023
Grafana information disclosure
High
CVE-2020-12458
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Password stored in a recoverable format by Jenkins OpenId Connect Authentication Plugin
Moderate
CVE-2023-50770
was published
for
org.jenkins-ci.plugins:oic-auth
(Maven)
Dec 13, 2023
Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about...
Low
Unreviewed
CVE-2024-46383
was published
Nov 15, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Moderate
CVE-2024-47529
was published
for
@openc3/tool-common
(RubyGems)
Oct 2, 2024
Moodle has user information visibility control issues in gradebook reports
Low
CVE-2024-43429
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email...
Moderate
Unreviewed
CVE-2021-34544
was published
Dec 8, 2021
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain...
Moderate
Unreviewed
CVE-2024-10523
was published
Nov 4, 2024
A user with permission to log on to the machine hosting the AXIS Device Manager client could...
Moderate
Unreviewed
CVE-2021-31989
was published
May 24, 2022
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created...
Moderate
Unreviewed
CVE-2020-11918
was published
Nov 7, 2024
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100...
Moderate
Unreviewed
CVE-2024-34891
was published
Nov 4, 2024
The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores...
Low
Unreviewed
CVE-2024-40594
was published
Jul 6, 2024
Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to...
High
Unreviewed
CVE-2024-28327
was published
Apr 26, 2024
An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted...
Low
Unreviewed
CVE-2023-46294
was published
May 1, 2024
No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command...
Critical
Unreviewed
CVE-2024-40457
was published
Sep 12, 2024
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information,...
Moderate
Unreviewed
CVE-2024-7783
was published
Oct 29, 2024
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in...
High
Unreviewed
CVE-2024-9991
was published
Oct 25, 2024
Sensitive data written to disk unencrypted in Spark
High
CVE-2019-10099
was published
for
org.apache.spark:spark-core_2.11
(Maven)
Aug 8, 2019
SaltStack Salt Cleartext Storage of Sensitive Information via cmdmod
Moderate
CVE-2021-25284
was published
for
salt
(pip)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API