GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,605
Maven
5,000+
npm
4,250
NuGet
756
pip
4,016
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
46 advisories
Filter by severity
Jenkins WSO2 Oauth Plugin stores WSO2 Oauth client secret unencrypted in global config.xml file on Jenkins controller
Low
CVE-2023-30527
was published
for
org.jenkins-ci.plugins:wso2id-oauth
(Maven)
Apr 12, 2023
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in...
Low
Unreviewed
CVE-2023-23776
was published
Mar 7, 2023
Logins saved by Firefox should be managed by the Password Manager component which uses encryption...
Low
Unreviewed
CVE-2022-42931
was published
Dec 22, 2022
Jenkins BigPanda Notifier Plugin Missing Password Field Masking
Low
CVE-2022-41248
was published
for
org.jenkins-ci.plugins:bigpanda-jenkins
(Maven)
Sep 22, 2022
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text...
Low
Unreviewed
CVE-2019-4566
was published
May 24, 2022
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory...
Low
Unreviewed
CVE-2020-15485
was published
May 24, 2022
A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy...
Low
Unreviewed
CVE-2020-7516
was published
May 24, 2022
BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at...
Low
Unreviewed
CVE-2019-18254
was published
May 24, 2022
Passwords stored in plain text by Jenkins Artifactory Plugin
Low
CVE-2020-2164
was published
for
org.jenkins-ci.plugins:artifactory
(Maven)
May 24, 2022
A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR...
Low
Unreviewed
CVE-2019-19291
was published
May 24, 2022
Jenkins Zephyr for JIRA Test Management Plugin stores credentials in plain text
Low
CVE-2020-2154
was published
for
org.jenkins-ci.plugins:zephyr-for-jira-test-management
(Maven)
May 24, 2022
Katello cleartext password storage issue
Low
CVE-2019-14825
was published
for
katello
(RubyGems)
May 24, 2022
Cleartext Storage of Sensitive Information in Jenkins ElasticBox CI Plugin
Low
CVE-2019-10450
was published
for
com.elasticbox.jenkins-ci.plugins:elasticbox
(Maven)
May 24, 2022
DingTalk Plugin stores credentials in plain text
Low
CVE-2019-10433
was published
for
io.jenkins.plugins:dingding-notifications
(Maven)
May 24, 2022
Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
Low
Unreviewed
CVE-2022-28162
was published
May 10, 2022
Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in...
Low
Unreviewed
CVE-2009-1466
was published
May 2, 2022
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish...
Low
Unreviewed
CVE-2008-1567
was published
May 1, 2022
Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext...
Low
Unreviewed
CVE-2005-2209
was published
May 1, 2022
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a...
Low
Unreviewed
CVE-2002-1696
was published
Apr 30, 2022
Parse Server stores password in plain text
Low
CVE-2020-26288
was published
for
parse-server
(npm)
Dec 28, 2020
Apache Airflow logs passwords in plaintext
Low
CVE-2020-17511
was published
for
apache-airflow
(pip)
Dec 17, 2020
ProTip!
Advisories are also available from the
GraphQL API