GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,086 advisories
Filter by severity
Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and...
High
Unreviewed
CVE-2022-24610
was published
Feb 25, 2022
IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain...
Moderate
Unreviewed
CVE-2021-39026
was published
Feb 19, 2022
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to...
Moderate
Unreviewed
CVE-2022-24982
was published
Feb 17, 2022
Jenkins Pipeline: Groovy Plugin has Insufficiently Protected Credentials
Moderate
CVE-2022-25180
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
Feb 16, 2022
Password parameter default values exposed by Jenkins Pipeline: Build Step Plugin
Moderate
CVE-2022-25184
was published
for
org.jenkins-ci.plugins:pipeline-build-step
(Maven)
Feb 16, 2022
Jenkins Support Core Plugin stores sensitive data in plain text
Moderate
CVE-2022-25187
was published
for
org.jenkins-ci.plugins:support-core
(Maven)
Feb 16, 2022
containers/image library Insufficiently Protects Credentials
Moderate
CVE-2019-10214
was published
for
github.com/containers/image
(Go)
Feb 15, 2022
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive...
High
Unreviewed
CVE-2021-22798
was published
Feb 12, 2022
containerd v1.2.x can be coerced into leaking credentials during image pull
Moderate
CVE-2020-15157
was published
for
github.com/containerd/containerd
(Go)
Feb 11, 2022
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0...
Moderate
Unreviewed
CVE-2021-33107
was published
Feb 11, 2022
An insufficiently protected credentials vulnerability exists in the Palo Alto Networks...
Moderate
Unreviewed
CVE-2022-0019
was published
Feb 11, 2022
Insufficiently Protected Credentials in Reactor Netty
Moderate
CVE-2020-5404
was published
for
io.projectreactor.netty:reactor-netty-http
(Maven)
Feb 10, 2022
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS...
High
Unreviewed
CVE-2021-40360
was published
Feb 10, 2022
Insufficiently Protected Credentials in Apache Superset
High
CVE-2021-44451
was published
for
apache-superset
(pip)
Feb 2, 2022
Password exposure in ShenYu
High
CVE-2022-23223
was published
for
org.apache.shenyu:shenyu-common
(Maven)
Jan 28, 2022
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials...
Moderate
Unreviewed
CVE-2022-22554
was published
Jan 25, 2022
The web application on Agilia Link+ version 3.0 implements authentication and session management...
Critical
Unreviewed
CVE-2021-23196
was published
Jan 22, 2022
An attacker with physical access to the host can extract the secrets from the registry and create...
Moderate
Unreviewed
CVE-2021-23207
was published
Jan 22, 2022
Users with appropriate file access may be able to access unencrypted user credentials saved by...
Moderate
Unreviewed
CVE-2021-32039
was published
Jan 21, 2022
Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier...
Moderate
Unreviewed
CVE-2022-0184
was published
Jan 18, 2022
Access key stored in plain text by Jenkins Metrics Plugin
Moderate
CVE-2022-20621
was published
for
org.jenkins-ci.plugins:metrics
(Maven)
Jan 13, 2022
Improper credentials masking in Jenkins HashiCorp Vault Plugin
Moderate
CVE-2022-23109
was published
for
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
(Maven)
Jan 13, 2022
Password stored in plain text by Jenkins Publish Over SSH Plugin
Low
CVE-2022-23114
was published
for
org.jenkins-ci.plugins:publish-over-ssh
(Maven)
Jan 13, 2022
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin.
High
CVE-2021-45457
was published
for
org.apache.kylin:kylin
(Maven)
Jan 8, 2022
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb...
Moderate
Unreviewed
CVE-2021-20164
was published
Dec 31, 2021
ProTip!
Advisories are also available from the
GraphQL API