GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
820 advisories
Filter by severity
VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor...
Moderate
Unreviewed
CVE-2024-22266
was published
May 8, 2024
An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked...
Moderate
Unreviewed
CVE-2023-50436
was published
Feb 29, 2024
In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software...
Moderate
Unreviewed
CVE-2024-47588
was published
Nov 12, 2024
Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By...
Moderate
Unreviewed
CVE-2024-29216
was published
Mar 25, 2024
An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an...
High
Unreviewed
CVE-2024-51240
was published
Nov 5, 2024
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote...
High
Unreviewed
CVE-2024-6492
was published
Jul 16, 2024
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100...
Moderate
Unreviewed
CVE-2024-34887
was published
Nov 4, 2024
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100...
Moderate
Unreviewed
CVE-2024-34883
was published
Nov 4, 2024
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100...
Moderate
Unreviewed
CVE-2024-34882
was published
Nov 4, 2024
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100...
Moderate
Unreviewed
CVE-2024-34885
was published
Nov 4, 2024
HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network...
High
Unreviewed
CVE-2024-29071
was published
Mar 25, 2024
An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout,...
Moderate
Unreviewed
CVE-2024-26330
was published
Jun 11, 2024
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform...
Moderate
Unreviewed
CVE-2024-20462
was published
Oct 16, 2024
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical...
Moderate
Unreviewed
CVE-2024-31800
was published
Aug 15, 2024
An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to...
High
Unreviewed
CVE-2023-31824
was published
Jul 13, 2023
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119...
Moderate
Unreviewed
CVE-2022-4926
was published
Jul 29, 2023
HPE OneView may have a missing passphrase during restore.
Moderate
Unreviewed
CVE-2023-6573
was published
Jan 23, 2024
Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow...
High
Unreviewed
CVE-2023-49233
was published
Sep 3, 2024
IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication...
Moderate
Unreviewed
CVE-2023-50310
was published
Oct 23, 2024
Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which...
High
Unreviewed
CVE-2024-43812
was published
Oct 23, 2024
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H...
Moderate
Unreviewed
CVE-2024-9677
was published
Oct 22, 2024
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache...
Critical
Unreviewed
CVE-2024-44000
was published
Oct 20, 2024
The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is...
High
Unreviewed
CVE-2024-7755
was published
Oct 17, 2024
The affected product is vulnerable due to insufficiently protected credentials, which may allow...
High
Unreviewed
CVE-2024-49396
was published
Oct 17, 2024
IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that...
Moderate
Unreviewed
CVE-2022-38714
was published
Feb 12, 2024
ProTip!
Advisories are also available from the
GraphQL API