GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,318
Maven
5,000+
npm
3,950
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
601 advisories
Filter by severity
IBM InfoSphere Information Server 11.7 stores credential information for database authentication...
Moderate
Unreviewed
CVE-2025-1499
was published
Jun 1, 2025
Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including...
High
Unreviewed
CVE-2025-44614
was published
May 30, 2025
Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A...
Moderate
Unreviewed
CVE-2025-32752
was published
May 29, 2025
Mautic does not shield .env files from web traffic
Moderate
CVE-2024-47056
was published
for
mautic/core
(Composer)
May 28, 2025
The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access...
Moderate
Unreviewed
CVE-2025-4053
was published
May 26, 2025
A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on...
Moderate
Unreviewed
CVE-2025-5154
was published
May 25, 2025
The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext...
Moderate
Unreviewed
CVE-2024-56428
was published
May 21, 2025
Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant)...
Moderate
Unreviewed
CVE-2025-4737
was published
May 15, 2025
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic....
Low
Unreviewed
CVE-2025-4537
was published
May 11, 2025
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro...
High
Unreviewed
CVE-2025-46633
was published
May 2, 2025
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro...
High
Unreviewed
CVE-2025-46634
was published
May 2, 2025
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information...
High
Unreviewed
CVE-2025-3395
was published
Apr 30, 2025
A vulnerability in the “Backup & Restore” functionality of the web application of ctrlX OS allows...
Moderate
Unreviewed
CVE-2025-27532
was published
Apr 30, 2025
A vulnerability in the Palo Alto Networks PAN-OS® software enables unlicensed administrators to...
Moderate
Unreviewed
CVE-2025-0123
was published
Apr 11, 2025
This vulnerability exists in TP-Link Tapo H200 V1 IoT Smart Hub due to storage of Wi-Fi...
Moderate
Unreviewed
CVE-2025-3442
was published
Apr 9, 2025
Jenkins AsakusaSatellite Plugin Stores API Keys Unencrypted in Job `config.xml` Files
Moderate
CVE-2025-31727
was published
for
org.codefirst.jenkins.asakusasatellite:asakusa-satellite-plugin
(Maven)
Apr 2, 2025
Jenkins Stack Hammer Plugin Stores API Keys Unencrypted in Job `config.xml` Files
Moderate
CVE-2025-31726
was published
for
org.jenkins-ci.plugins:stackhammer
(Maven)
Apr 2, 2025
Jenkins Cadence vManager Plugin Stores Verisium Manager vAPI keys Unencrypted
Moderate
CVE-2025-31724
was published
for
org.jenkins-ci.plugins:vmanager-plugin
(Maven)
Apr 2, 2025
Jenkins monitor-remote-job Plugin Stores Passwords Unencrypted
Moderate
CVE-2025-31725
was published
for
org.ukiuni.monitor-remote-job-plugin:monitor-remote-job
(Maven)
Apr 2, 2025
Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who...
Moderate
Unreviewed
CVE-2025-0418
was published
Apr 1, 2025
The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3...
Moderate
Unreviewed
CVE-2025-2909
was published
Mar 28, 2025
An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data...
High
Unreviewed
CVE-2025-25758
was published
Mar 20, 2025
This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext...
Moderate
Unreviewed
CVE-2025-2189
was published
Mar 11, 2025
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery...
High
Unreviewed
CVE-2024-12604
was published
Mar 10, 2025
A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been rated as...
Low
Unreviewed
CVE-2025-2120
was published
Mar 9, 2025
ProTip!
Advisories are also available from the
GraphQL API