GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,697
Erlang
34
GitHub Actions
28
Go
2,289
Maven
5,000+
npm
3,936
NuGet
708
pip
3,706
Pub
12
RubyGems
919
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
170 advisories
Filter by severity
The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive...
Moderate
Unreviewed
CVE-2023-33228
was published
Nov 1, 2023
Jenkins VS Team Services Continuous Deployment Plugin stores credentials in plain text
Moderate
CVE-2019-1003073
was published
for
org.jenkins-ci.plugins:vsts-cd
(Maven)
May 13, 2022
The application was vulnerable to an authenticated information disclosure, allowing...
Moderate
Unreviewed
CVE-2022-40295
was published
Nov 1, 2022
Passwords stored in plain text by Jenkins ReadyAPI Functional Testing Plugin
Moderate
CVE-2020-2250
was published
for
org.jenkins-ci.plugins:soapui-pro-functional-testing
(Maven)
May 24, 2022
Jenkins wildFly Deployer Plugin stores credentials in plain text
Moderate
CVE-2019-1003072
was published
for
org.jenkins-ci.plugins:wildfly-deployer
(Maven)
May 13, 2022
Jenkins Trac Publisher Plugin stores credentials in plain text
Moderate
CVE-2019-1003067
was published
for
org.jenkins-ci.plugins:trac-publisher-plugin
(Maven)
May 13, 2022
Jenkins VMware vRealize Automation Plugin Missing Encryption of Sensitive Data
Moderate
CVE-2019-1003068
was published
for
com.inkysea.vmware.vra:vmware-vrealize-automation-plugin
(Maven)
May 13, 2022
Jenkins Jira Issue Updater Plugin stores credentials in plain text
Moderate
CVE-2019-1003054
was published
for
info.bluefloyd.jenkins:jenkins-jira-issue-updater
(Maven)
May 13, 2022
Jenkins WebSphere Deployer Plugin stores credentials in plain text
Moderate
CVE-2019-1003056
was published
for
org.jenkins-ci.plugins:websphere-deployer
(Maven)
May 13, 2022
Dashlane password and Keepass Server password in My Account Settings are not encrypted in the...
Moderate
Unreviewed
CVE-2022-3781
was published
Nov 2, 2022
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only...
Moderate
Unreviewed
CVE-2022-26390
was published
Sep 10, 2022
usememos/memos missing Secure cookie attribute
Moderate
CVE-2022-4683
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The...
Moderate
Unreviewed
CVE-2021-27764
was published
May 7, 2022
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 ...
Moderate
Unreviewed
CVE-2022-24045
was published
May 21, 2022
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls...
Moderate
Unreviewed
CVE-2022-21940
was published
Feb 9, 2023
Docker Swarm encrypted overlay network traffic may be unencrypted
Moderate
CVE-2023-28841
was published
for
github.com/docker/docker
(Go)
Apr 4, 2023
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear...
Moderate
Unreviewed
CVE-2022-38458
was published
Mar 21, 2023
In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.
Moderate
Unreviewed
CVE-2022-47715
was published
Feb 1, 2023
In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore...
Moderate
Unreviewed
CVE-2023-23127
was published
Feb 1, 2023
An information disclosure vulnerability exists in the Web Server functionality of Sealevel...
Moderate
Unreviewed
CVE-2021-21963
was published
Feb 9, 2022
Missing encryption of sensitive data vulnerability in 'MIRUPASS' PW10 firmware all versions and ...
Moderate
Unreviewed
CVE-2022-0183
was published
Jan 18, 2022
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on...
Moderate
Unreviewed
CVE-2019-4171
was published
May 24, 2022
The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the...
Moderate
Unreviewed
CVE-2018-6976
was published
May 13, 2022
Plaintext of decrypted emails can leak through by user submitting an embedded form. This...
Moderate
Unreviewed
CVE-2018-5185
was published
May 13, 2022
NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an...
Moderate
Unreviewed
CVE-2018-5482
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API