GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,064
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,067 advisories
Filter by severity
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3...
High
Unreviewed
CVE-2018-11634
was published
May 13, 2022
Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.
High
Unreviewed
CVE-2018-10814
was published
May 13, 2022
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow...
High
Unreviewed
CVE-2018-10355
was published
May 13, 2022
PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding,...
High
Unreviewed
CVE-2018-10327
was published
May 13, 2022
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS...
High
Unreviewed
CVE-2018-10286
was published
May 13, 2022
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in...
Critical
Unreviewed
CVE-2018-10024
was published
May 13, 2022
Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by...
Critical
Unreviewed
CVE-2018-1000627
was published
May 13, 2022
Jenkins Configuration as Code Plugin has Insufficiently Protected Credentials
High
CVE-2018-1000610
was published
for
io.jenkins:configuration-as-code
(Maven)
May 13, 2022
Jenkins z/OS Connector Plugin allows local attacker to retrieve configured password
Low
CVE-2018-1000608
was published
for
org.jenkins-ci.plugins:zos-connector
(Maven)
May 13, 2022
AWS CodeDeploy Plugin stored AWS Secret Key in plain text
High
CVE-2018-1000403
was published
for
com.amazonaws:codedeploy
(Maven)
May 13, 2022
Jenkins AWS CodePipeline Plugin has Insufficiently Protected Credentials
High
CVE-2018-1000401
was published
for
com.amazonaws:aws-codepipeline
(Maven)
May 13, 2022
Insufficiently Protected Credentials in Jenkins AWS CodeBuild Plugin
High
CVE-2018-1000404
was published
for
com.amazonaws:aws-codebuild
(Maven)
May 13, 2022
Jenkins Coverity Plugin has Insufficiently Protected Credentials
Low
CVE-2018-1000104
was published
for
org.jenkins-ci.plugins:coverity
(Maven)
May 13, 2022
Jenkins Credentials Binding Plugin has Insufficiently Protected Credentials
Moderate
CVE-2018-1000057
was published
for
org.jenkins-ci.plugins:credentials-binding
(Maven)
May 13, 2022
Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due...
High
Unreviewed
CVE-2018-0828
was published
May 13, 2022
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application...
Moderate
Unreviewed
CVE-2017-9969
was published
May 13, 2022
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity...
Critical
Unreviewed
CVE-2017-9248
was published
May 13, 2022
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices...
Critical
Unreviewed
CVE-2017-8837
was published
May 13, 2022
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for...
Moderate
Unreviewed
CVE-2017-8371
was published
May 13, 2022
kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of...
High
Unreviewed
CVE-2017-8296
was published
May 13, 2022
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not...
Critical
Unreviewed
CVE-2017-8225
was published
May 13, 2022
Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA...
High
Unreviewed
CVE-2017-8222
was published
May 13, 2022
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text...
Critical
Unreviewed
CVE-2017-7933
was published
May 13, 2022
A vulnerability in the Virtual Network Function Manager's (VNFM) logging function of Cisco Ultra...
Moderate
Unreviewed
CVE-2017-6694
was published
May 13, 2022
Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 have cleartext credentials in...
Critical
Unreviewed
CVE-2017-6532
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API