GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            653 advisories
        Filter by severity
        
      
      
    
                    
                      The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-5359
                      
                      was published
                      Sep 25, 2024 
                    
                  
                    
                      The configuration file stores credentials in cleartext. An attacker with local access rights can...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-6785
                      
                      was published
                      Sep 21, 2024 
                    
                  
                    
                      A vulnerability, which was classified as problematic, was found in code-projects Blood Bank...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-9040
                      
                      was published
                      Sep 20, 2024 
                    
                  
                    
                      Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-45862
                      
                      was published
                      Sep 19, 2024 
                    
                  
                    
                      The Eaton Foreseer software provides the feasibility for the user to configure external servers...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-31415
                      
                      was published
                      Sep 13, 2024 
                    
                  
                    
                      An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-41629
                      
                      was published
                      Sep 12, 2024 
                    
                  
                    
                      No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-40457
                      
                      was published
                      Sep 12, 2024 
                    
                  
                    
                      A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-8689
                      
                      was published
                      Sep 11, 2024 
                    
                  
                    
                      A cleartext storage of sensitive information in memory vulnerability [CWE-316] affecting...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-35282
                      
                      was published
                      Sep 10, 2024 
                    
                  
                    
                      In the Linux kernel, the following vulnerability has been resolved:
KEYS: trusted: dcp: fix leak...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-45004
                      
                      was published
                      Sep 4, 2024 
                    
                  
                    
                      Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-41716
                      
                      was published
                      Sep 4, 2024 
                    
                  
                    
                      Tina search token leak via lock file in TinaCMS
                    
                      
  High
                    
                
                      
                        CVE-2024-45391
                      
                      was published
                        for
                        
                          @tinacms/cli
                        
                        (npm)
                      Sep 3, 2024 
                    
                  
                    
                      Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc....
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-6921
                      
                      was published
                      Sep 2, 2024 
                    
                  
                    
                      A vulnerability identified in storing and reusing information in Advance Authentication. This...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-22509
                      
                      was published
                      Aug 28, 2024 
                    
                  
                    
                      Mattermost doesn't redact remote users' original email addresses
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-32939
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost/server/v8
                        
                        (Go)
                      Aug 22, 2024 
                    
                  
                    
                      IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-25024
                      
                      was published
                      Aug 15, 2024 
                    
                  
                    
                      An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-5916
                      
                      was published
                      Aug 14, 2024 
                    
                  
                    
                      Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-33892
                      
                      was published
                      Aug 2, 2024 
                    
                  
                    
                      A vulnerability has been identified in Omnivise T3000 Application Server (All versions), Omnivise...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-38877
                      
                      was published
                      Aug 2, 2024 
                    
                  
                    
                      This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-41690
                      
                      was published
                      Jul 26, 2024 
                    
                  
                    
                      This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-41691
                      
                      was published
                      Jul 26, 2024 
                    
                  
                    
                      This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-41689
                      
                      was published
                      Jul 26, 2024 
                    
                  
                    
                      This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-41688
                      
                      was published
                      Jul 26, 2024 
                    
                  
                    
                      Plaintext vulnerability in the Gallery search module.
Impact: Successful exploitation of this...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39674
                      
                      was published
                      Jul 25, 2024 
                    
                  
                    
                      An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-16638
                      
                      was published
                      Jul 16, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API