GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,699
Erlang
34
GitHub Actions
28
Go
2,292
Maven
5,000+
npm
3,941
NuGet
708
pip
3,708
Pub
12
RubyGems
919
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
170 advisories
Filter by severity
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to...
Moderate
Unreviewed
CVE-2021-39090
was published
Feb 29, 2024
Unencrypted traffic between pods when using Wireguard and an external kvstore
Moderate
CVE-2024-25631
was published
for
github.com/cilium/cilium
(Go)
Feb 20, 2024
Unencrypted ingress/health traffic when using Wireguard transparent encryption
Moderate
CVE-2024-25630
was published
for
github.com/cilium/cilium
(Go)
Feb 20, 2024
Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow...
Moderate
Unreviewed
CVE-2023-50126
was published
Jan 11, 2024
Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create...
Moderate
Unreviewed
CVE-2023-50129
was published
Jan 11, 2024
IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0...
Moderate
Unreviewed
CVE-2023-38267
was published
Jan 11, 2024
When saving HSTS data to an excessively long file name, curl could end up
removing all contents,...
Moderate
Unreviewed
CVE-2023-46219
was published
Dec 12, 2023
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of...
Moderate
Unreviewed
CVE-2023-42019
was published
Dec 1, 2023
The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive...
Moderate
Unreviewed
CVE-2023-33228
was published
Nov 1, 2023
Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM ...
Moderate
Unreviewed
CVE-2023-41096
was published
Oct 26, 2023
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2022-22386
was published
Oct 17, 2023
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2022-22377
was published
Oct 17, 2023
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information...
Moderate
Unreviewed
CVE-2022-33161
was published
Oct 14, 2023
A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN...
Moderate
Unreviewed
CVE-2023-23371
was published
Oct 6, 2023
Croc requires senders to provide local IP addresses in cleartext
Moderate
CVE-2023-43618
was published
for
github.com/schollz/croc/v9
(Go)
Sep 20, 2023
Push notifications stored on disk in private browsing mode were not being encrypted potentially...
Moderate
Unreviewed
CVE-2023-4580
was published
Sep 11, 2023
IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by...
Moderate
Unreviewed
CVE-2022-22405
was published
Sep 8, 2023
Missing Encryption of Sensitive DataCAPEC- vulnerability in Genians Genian NAC V4.0, Genians...
Moderate
Unreviewed
CVE-2023-40251
was published
Aug 17, 2023
Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to...
Moderate
Unreviewed
CVE-2023-39841
was published
Aug 15, 2023
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated,...
Moderate
Unreviewed
CVE-2023-37858
was published
Aug 9, 2023
The data flowing between the PCU and its modules is insecure. A threat actor with physical access...
Moderate
Unreviewed
CVE-2023-30561
was published
Jul 13, 2023
Jenkins Active Directory Plugin vulnerable to Active Directory credential disclosure
Moderate
CVE-2023-37943
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
Jul 12, 2023
Jenkins Ansible Plugin stores and displays secrets in plain text
Moderate
CVE-2023-32982
was published
for
org.jenkins-ci.plugins:ansible
(Maven)
May 16, 2023
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific...
Moderate
Unreviewed
CVE-2023-21404
was published
May 8, 2023
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access...
Moderate
Unreviewed
CVE-2023-22948
was published
Apr 13, 2023
ProTip!
Advisories are also available from the
GraphQL API