GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,747
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
185 advisories
Filter by severity
Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including...
High
Unreviewed
CVE-2025-44614
was published
May 30, 2025
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro...
High
Unreviewed
CVE-2025-46633
was published
May 2, 2025
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro...
High
Unreviewed
CVE-2025-46634
was published
May 2, 2025
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information...
High
Unreviewed
CVE-2025-3395
was published
Apr 30, 2025
An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data...
High
Unreviewed
CVE-2025-25758
was published
Mar 20, 2025
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery...
High
Unreviewed
CVE-2024-12604
was published
Mar 10, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330...
High
Unreviewed
CVE-2025-27685
was published
Mar 5, 2025
Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record...
High
Unreviewed
CVE-2025-26495
was published
Feb 11, 2025
Navidrome Stores JWT Secret in Plaintext in navidrome.db
High
CVE-2024-56362
was published
for
github.com/navidrome/navidrome
(Go)
Dec 23, 2024
GoPhish sends cleartext passwords
High
CVE-2024-55196
was published
for
github.com/gophish/gophish
(Go)
Dec 19, 2024
An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the...
High
Unreviewed
CVE-2024-51175
was published
Dec 18, 2024
TP-Link TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to transmit user...
High
Unreviewed
CVE-2024-46340
was published
Dec 10, 2024
Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.
High
Unreviewed
CVE-2024-40582
was published
Dec 9, 2024
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved...
High
Unreviewed
CVE-2024-42451
was published
Dec 4, 2024
This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in...
High
Unreviewed
CVE-2024-9991
was published
Oct 25, 2024
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test...
High
Unreviewed
CVE-2024-8070
was published
Oct 13, 2024
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition...
High
Unreviewed
CVE-2024-9466
was published
Oct 9, 2024
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive...
High
Unreviewed
CVE-2024-25661
was published
Oct 1, 2024
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in...
High
Unreviewed
CVE-2024-28809
was published
Sep 30, 2024
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within...
High
Unreviewed
CVE-2024-8459
was published
Sep 30, 2024
Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may...
High
Unreviewed
CVE-2024-45862
was published
Sep 19, 2024
Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If...
High
Unreviewed
CVE-2024-41716
was published
Sep 4, 2024
Tina search token leak via lock file in TinaCMS
High
CVE-2024-45391
was published
for
@tinacms/cli
(npm)
Sep 3, 2024
Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc....
High
Unreviewed
CVE-2024-6921
was published
Sep 2, 2024
A vulnerability identified in storing and reusing information in Advance Authentication. This...
High
Unreviewed
CVE-2021-22509
was published
Aug 28, 2024
ProTip!
Advisories are also available from the
GraphQL API