GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
649 advisories
Filter by severity
Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.
Low
Unreviewed
CVE-2025-47820
was published
Jun 27, 2025
Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could...
Moderate
Unreviewed
CVE-2025-48428
was published
Oct 23, 2025
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to...
Moderate
Unreviewed
CVE-2011-4723
was published
May 17, 2022
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an...
High
Unreviewed
CVE-2020-29583
was published
May 24, 2022
Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2025-55334
was published
Oct 14, 2025
The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used...
Moderate
Unreviewed
CVE-2025-59450
was published
Oct 6, 2025
Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi...
High
Unreviewed
CVE-2025-59409
was published
Oct 2, 2025
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage...
Low
Unreviewed
CVE-2025-47824
was published
Jun 27, 2025
Lightbend Alpakka Kafka logs credentials on debug level
Moderate
CVE-2023-29471
was published
for
com.typesafe.akka:akka-stream-kafka_2.11
(Maven)
Apr 27, 2023
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an...
Low
Unreviewed
CVE-2025-23291
was published
Sep 30, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS...
Critical
Unreviewed
CVE-2025-34206
was published
Sep 19, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS...
High
Unreviewed
CVE-2025-34200
was published
Sep 19, 2025
Cleartext storage of sensitive information was discovered in Click Programming Software version...
Moderate
Unreviewed
CVE-2025-54855
was published
Sep 24, 2025
Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized...
Moderate
Unreviewed
CVE-2025-49728
was published
Sep 16, 2025
Jenkins Applitools Eyes Plugin vulnerability exposes unencrypted keys to certain authenticated users
Moderate
CVE-2025-53742
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form....
Moderate
Unreviewed
CVE-2025-58401
was published
Sep 5, 2025
Credentials are not cleared from memory after being used. A user with Administrator permissions...
Moderate
Unreviewed
CVE-2024-24915
was published
Jun 29, 2025
Local Deep Research's API keys are stored in plain text
Moderate
CVE-2025-57806
was published
for
local-deep-research
(pip)
Sep 2, 2025
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text
High
CVE-2024-52284
was published
for
github.com/rancher/fleet
(Go)
Aug 29, 2025
Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT...
Critical
Unreviewed
CVE-2025-55443
was published
Aug 26, 2025
The Eaton Foreseer software provides the feasibility for the user to configure external servers...
Moderate
Unreviewed
CVE-2024-31415
was published
Sep 13, 2024
A local user may find a configuration file on the client workstation with unencrypted sensitive...
High
Unreviewed
CVE-2024-23942
was published
Mar 18, 2025
BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability...
Moderate
Unreviewed
CVE-2025-2770
was published
Apr 23, 2025
A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud...
Moderate
Unreviewed
CVE-2025-2181
was published
Aug 13, 2025
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in...
Moderate
Unreviewed
CVE-2025-2182
was published
Aug 13, 2025
ProTip!
Advisories are also available from the
GraphQL API