GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,343
Erlang
31
GitHub Actions
22
Go
2,107
Maven
5,000+
npm
3,764
NuGet
679
pip
3,452
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
469 advisories
Filter by severity
python-oslo-utils has improper password parsing
Moderate
CVE-2022-0718
was published
for
oslo-utils
(pip)
Aug 29, 2022
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who...
Moderate
Unreviewed
CVE-2022-34837
was published
Aug 25, 2022
Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an...
Moderate
Unreviewed
CVE-2020-35992
was published
Aug 24, 2022
Improper masking of credentials Jenkins in Git Plugin
Moderate
CVE-2022-38663
was published
for
org.jenkins-ci.plugins:git
(Maven)
Aug 24, 2022
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions...
Moderate
Unreviewed
CVE-2022-29507
was published
Aug 19, 2022
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may...
Moderate
Unreviewed
CVE-2022-30944
was published
Aug 19, 2022
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering...
Moderate
Unreviewed
CVE-2022-29959
was published
Aug 17, 2022
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat...
Moderate
Unreviewed
CVE-2020-10710
was published
Aug 17, 2022
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE...
Moderate
Unreviewed
CVE-2022-20914
was published
Aug 11, 2022
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials...
Moderate
Unreviewed
CVE-2022-22983
was published
Aug 11, 2022
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently...
Moderate
Unreviewed
CVE-2022-33169
was published
Aug 2, 2022
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal...
Moderate
Unreviewed
CVE-2021-27785
was published
Jul 31, 2022
BigFix Web Reports authorized users may see SMTP credentials in clear text.
Moderate
Unreviewed
CVE-2022-27544
was published
Jul 20, 2022
HCL Launch stores user credentials in plain clear text which can be read by a local user.
Moderate
Unreviewed
CVE-2022-27548
was published
Jul 7, 2022
Jenkins OpsGenie Plugin Plaintext Storage of a Password vulnerability
Moderate
CVE-2022-34803
was published
for
org.jenkins-ci.plugins:opsgenie
(Maven)
Jul 1, 2022
Jenkins Deployment Dashboard Plugin has Insufficiently Protected Credentials
Moderate
CVE-2022-34796
was published
for
org.jenkins-ci.plugins:ec2-deployment-dashboard
(Maven)
Jul 1, 2022
Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager...
Moderate
Unreviewed
CVE-2022-2221
was published
Jun 28, 2022
IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the...
Moderate
Unreviewed
CVE-2022-33953
was published
Jun 25, 2022
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active...
Moderate
Unreviewed
CVE-2021-30651
was published
Jun 25, 2022
The default password for the web application’s root user (the vendor’s private account) was weak...
Moderate
Unreviewed
CVE-2022-1666
was published
Jun 25, 2022
Plaintext Storage of a Password in Jenkins Convertigo Mobile Platform Plugin
Moderate
CVE-2022-34199
was published
for
com.convertigo.jenkins.plugins:convertigo-mobile-platform
(Maven)
Jun 24, 2022
Insufficiently Protected Credentials via Insecure Temporary File in org.apache.nifi:nifi-single-user-utils
Moderate
CVE-2022-26850
was published
for
org.apache.nifi:nifi-single-user-utils
(Maven)
Jun 20, 2022
An information disclosure vulnerability exists in the License registration functionality of...
Moderate
Unreviewed
CVE-2022-21184
was published
Jun 18, 2022
A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate...
Moderate
Unreviewed
CVE-2022-1342
was published
Jun 16, 2022
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6),...
Moderate
Unreviewed
CVE-2022-30231
was published
Jun 15, 2022
ProTip!
Advisories are also available from the
GraphQL API