GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
466 advisories
Filter by severity
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
Moderate
Unreviewed
CVE-2020-24622
was published
May 24, 2022
An HPE OneView appliance dump may expose SNMPv3 read credentials
Moderate
Unreviewed
CVE-2023-28090
was published
Apr 25, 2023
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
Moderate
Unreviewed
CVE-2023-28084
was published
Apr 25, 2023
A valid, authenticated administrative user can query a web interface API to reveal the configured...
Moderate
Unreviewed
CVE-2023-25495
was published
Apr 29, 2023
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4...
Moderate
Unreviewed
CVE-2022-45859
was published
May 4, 2023
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive...
Moderate
Unreviewed
CVE-2023-28764
was published
May 9, 2023
Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow...
Moderate
Unreviewed
CVE-2022-40685
was published
May 10, 2023
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote,...
Moderate
Unreviewed
CVE-2022-47880
was published
May 12, 2023
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool...
Moderate
Unreviewed
CVE-2023-1763
was published
May 17, 2023
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
Moderate
Unreviewed
CVE-2023-31187
was published
May 30, 2023
The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build...
Moderate
Unreviewed
CVE-2023-27126
was published
Jun 6, 2023
GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which...
Moderate
Unreviewed
CVE-2023-33620
was published
Jun 13, 2023
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ...
Moderate
Unreviewed
CVE-2023-35789
was published
Jun 16, 2023
Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve...
Moderate
Unreviewed
CVE-2022-28291
was published
Jul 6, 2023
HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username...
Moderate
Unreviewed
CVE-2022-37935
was published
Jul 6, 2023
A pass-back vulnerability exists where an authenticated, remote attacker with administrator...
Moderate
Unreviewed
CVE-2023-3251
was published
Aug 29, 2023
IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores...
Moderate
Unreviewed
CVE-2023-32338
was published
Sep 5, 2023
Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom...
Moderate
Unreviewed
CVE-2023-41010
was published
Sep 14, 2023
An insufficiently protected credentials vulnerability has been reported to affect QVPN Device...
Moderate
Unreviewed
CVE-2023-23370
was published
Oct 6, 2023
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An...
Moderate
Unreviewed
CVE-2022-44758
was published
Oct 11, 2023
SnapGathers versions prior to 4.9 are susceptible to a vulnerability
which could allow a local...
Moderate
Unreviewed
CVE-2023-27315
was published
Oct 12, 2023
Eaton easySoft software is used to program easy controllers and displays for configuring,...
Moderate
Unreviewed
CVE-2023-43777
was published
Oct 17, 2023
An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability...
Moderate
Unreviewed
CVE-2023-38328
was published
Oct 27, 2023
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak...
Moderate
Unreviewed
CVE-2022-27776
was published
Jun 3, 2022
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82...
Moderate
Unreviewed
CVE-2022-27774
was published
Jun 3, 2022
ProTip!
Advisories are also available from the
GraphQL API