GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,293
Erlang
31
GitHub Actions
21
Go
2,061
Maven
5,000+
npm
3,744
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
359 advisories
Filter by severity
Incorrect access control in Zoho ManageEngine ADManager Plus Build 7180 allows unauthenticated...
Moderate
Unreviewed
CVE-2023-31492
was published
Aug 18, 2023
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys...
Moderate
Unreviewed
CVE-2023-4327
was published
Aug 15, 2023
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys...
Moderate
Unreviewed
CVE-2023-4328
was published
Aug 15, 2023
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119...
Moderate
Unreviewed
CVE-2022-4926
was published
Jul 29, 2023
An issue was discovered in Keeper Password Manager for Desktop version 16.10.2, and the...
Moderate
Unreviewed
CVE-2023-36266
was published
Jul 12, 2023
HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username...
Moderate
Unreviewed
CVE-2022-37935
was published
Jul 6, 2023
Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve...
Moderate
Unreviewed
CVE-2022-28291
was published
Jul 6, 2023
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ...
Moderate
Unreviewed
CVE-2023-35789
was published
Jun 16, 2023
GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which...
Moderate
Unreviewed
CVE-2023-33620
was published
Jun 13, 2023
The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build...
Moderate
Unreviewed
CVE-2023-27126
was published
Jun 6, 2023
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
Moderate
Unreviewed
CVE-2023-31187
was published
May 30, 2023
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool...
Moderate
Unreviewed
CVE-2023-1763
was published
May 17, 2023
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote,...
Moderate
Unreviewed
CVE-2022-47880
was published
May 12, 2023
Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow...
Moderate
Unreviewed
CVE-2022-40685
was published
May 10, 2023
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive...
Moderate
Unreviewed
CVE-2023-28764
was published
May 9, 2023
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4...
Moderate
Unreviewed
CVE-2022-45859
was published
May 4, 2023
A valid, authenticated administrative user can query a web interface API to reveal the configured...
Moderate
Unreviewed
CVE-2023-25495
was published
Apr 29, 2023
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
Moderate
Unreviewed
CVE-2023-28084
was published
Apr 25, 2023
An HPE OneView appliance dump may expose SNMPv3 read credentials
Moderate
Unreviewed
CVE-2023-28090
was published
Apr 25, 2023
Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote...
Moderate
Unreviewed
CVE-2023-1574
was published
Apr 2, 2023
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user...
Moderate
Unreviewed
CVE-2023-25686
was published
Mar 21, 2023
Insufficiently protected credentials in the Intel(R) ON Event Series Android application before...
Moderate
Unreviewed
CVE-2022-41614
was published
Feb 16, 2023
Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk...
Moderate
Unreviewed
CVE-2023-24619
was published
Feb 13, 2023
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A...
Moderate
Unreviewed
CVE-2022-34445
was published
Feb 11, 2023
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through...
Moderate
Unreviewed
CVE-2022-43959
was published
Jan 20, 2023
ProTip!
Advisories are also available from the
GraphQL API