GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
211 advisories
Filter by severity
Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information...
High
Unreviewed
CVE-2023-37879
was published
Sep 15, 2023
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile...
High
Unreviewed
CVE-2023-40728
was published
Sep 14, 2023
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information...
Moderate
Unreviewed
CVE-2023-29261
was published
Sep 5, 2023
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator...
Moderate
Unreviewed
CVE-2023-37439
was published
Aug 22, 2023
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions...
High
Unreviewed
CVE-2022-46484
was published
Aug 2, 2023
Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode...
Moderate
Unreviewed
CVE-2023-28864
was published
Jul 17, 2023
Exposure of sensitive information to an unauthorized actor issue exists in ELECOM wireless LAN...
Moderate
Unreviewed
CVE-2023-37563
was published
Jul 13, 2023
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been...
Moderate
Unreviewed
CVE-2023-23348
was published
Jul 10, 2023
Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate...
High
Unreviewed
CVE-2023-22687
was published
Jul 6, 2023
Default permissions for a properties file were too permissive. Local system users could read...
Low
Unreviewed
CVE-2023-26427
was published
Jun 20, 2023
Anonymous user may get the list of existing users managed by the application, that could ease...
Moderate
Unreviewed
CVE-2023-3064
was published
Jun 5, 2023
RosarioSIS Stores Sensitive Data in a Mechanism without Access Control
High
CVE-2023-2665
was published
for
francoisjacquet/rosariosis
(Composer)
May 19, 2023
A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering...
Moderate
Unreviewed
CVE-2023-31150
was published
May 10, 2023
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may...
High
Unreviewed
CVE-2022-44619
was published
May 10, 2023
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may...
High
Unreviewed
CVE-2022-43475
was published
May 10, 2023
IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information...
Moderate
Unreviewed
CVE-2022-43877
was published
May 6, 2023
Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise)...
Critical
Unreviewed
CVE-2023-0580
was published
Apr 6, 2023
Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view...
High
Unreviewed
CVE-2021-36546
was published
Feb 3, 2023
Publify Core does not strip metadata from images
Moderate
CVE-2022-2815
was published
for
publify_core
(RubyGems)
Jan 14, 2023
Logins saved by Firefox should be managed by the Password Manager component which uses encryption...
Low
Unreviewed
CVE-2022-42931
was published
Dec 22, 2022
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized...
Moderate
Unreviewed
CVE-2022-40959
was published
Dec 22, 2022
IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored...
Low
Unreviewed
CVE-2022-34354
was published
Nov 16, 2022
IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the...
Low
Unreviewed
CVE-2022-34312
was published
Nov 14, 2022
ezplatform-graphql GraphQL queries can expose password hashes
High
CVE-2022-41876
was published
for
ezsystems/ezplatform-graphql
(Composer)
Nov 10, 2022
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4...
Moderate
Unreviewed
CVE-2022-28170
was published
Oct 26, 2022
ProTip!
Advisories are also available from the
GraphQL API