GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,293
Erlang
31
GitHub Actions
21
Go
2,061
Maven
5,000+
npm
3,744
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
164 advisories
Filter by severity
Downloads Resources over HTTP in arcanist
Moderate
CVE-2016-10683
was published
for
arcanist
(npm)
Feb 18, 2019
Downloads Resources over HTTP in jser-stat
Moderate
CVE-2016-10592
was published
for
jser-stat
(npm)
Feb 18, 2019
Missing Encryption of Sensitive Data in arrow-kt Arrow
Moderate
CVE-2019-11404
was published
for
io.arrow-kt:arrow-ank-gradle
(Maven)
Apr 22, 2019
Downloads Resources over HTTP in adamvr-geoip-lite
Moderate
CVE-2016-10680
was published
for
adamvr-geoip-lite
(npm)
Sep 1, 2020
An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android....
Moderate
Unreviewed
CVE-2021-44518
was published
Dec 3, 2021
A missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below,...
Moderate
Unreviewed
CVE-2021-36189
was published
Dec 10, 2021
Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows decrypting secrets
Moderate
CVE-2022-23116
was published
for
org.conjur.jenkins:conjur-credentials
(Maven)
Jan 13, 2022
Missing encryption of sensitive data vulnerability in 'MIRUPASS' PW10 firmware all versions and ...
Moderate
Unreviewed
CVE-2022-0183
was published
Jan 18, 2022
An information disclosure vulnerability exists in the Web Server functionality of Sealevel...
Moderate
Unreviewed
CVE-2021-21963
was published
Feb 9, 2022
A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V5.6.0), RUGGEDCOM ROS...
Moderate
Unreviewed
CVE-2021-37209
was published
Mar 9, 2022
Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It...
Moderate
Unreviewed
CVE-2022-27225
was published
Mar 17, 2022
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS...
Moderate
Unreviewed
CVE-2012-5474
was published
Apr 23, 2022
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for...
Moderate
Unreviewed
CVE-2017-5042
was published
Apr 30, 2022
The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol...
Moderate
Unreviewed
CVE-2007-4961
was published
May 1, 2022
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The...
Moderate
Unreviewed
CVE-2021-27764
was published
May 7, 2022
Jenkins Upload to pgyer Plugin stores credentials in plain text
Moderate
CVE-2019-1003089
was published
for
ren.helloworld:upload-pgyer
(Maven)
May 13, 2022
Jenkins VS Team Services Continuous Deployment Plugin stores credentials in plain text
Moderate
CVE-2019-1003073
was published
for
org.jenkins-ci.plugins:vsts-cd
(Maven)
May 13, 2022
Jenkins wildFly Deployer Plugin stores credentials in plain text
Moderate
CVE-2019-1003072
was published
for
org.jenkins-ci.plugins:wildfly-deployer
(Maven)
May 13, 2022
Jenkins Perfecto Mobile Plugin stores credentials in plain text
Moderate
CVE-2019-1003095
was published
for
org.jenkins-ci.plugins:perfectomobile
(Maven)
May 13, 2022
Jenkins Fabric-beta-publisher Plugin stores credentials in plain text
Moderate
CVE-2019-1003088
was published
for
egor-n:fabric-beta-publisher
(Maven)
May 13, 2022
Jenkins Open STF Plugin stores credentials in plain text
Moderate
CVE-2019-1003094
was published
for
org.jenkins-ci.plugins:open-stf
(Maven)
May 13, 2022
Jenkins CloudFormation Plugin stores credentials in plain text
Moderate
CVE-2019-1003061
was published
for
org.jenkins-ci.plugins:jenkins-cloudformation-plugin
(Maven)
May 13, 2022
Jenkins VMware vRealize Automation Plugin Missing Encryption of Sensitive Data
Moderate
CVE-2019-1003068
was published
for
com.inkysea.vmware.vra:vmware-vrealize-automation-plugin
(Maven)
May 13, 2022
Jenkins Trac Publisher Plugin stores credentials in plain text
Moderate
CVE-2019-1003067
was published
for
org.jenkins-ci.plugins:trac-publisher-plugin
(Maven)
May 13, 2022
Jenkins Jira Issue Updater Plugin stores credentials in plain text
Moderate
CVE-2019-1003054
was published
for
info.bluefloyd.jenkins:jenkins-jira-issue-updater
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API