GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,747
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,139 advisories
Filter by severity
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access...
Moderate
Unreviewed
CVE-2025-2394
was published
May 23, 2025
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure...
Moderate
Unreviewed
CVE-2025-3480
was published
May 22, 2025
A passback vulnerability which relates to office/small office multifunction printers and laser...
Moderate
Unreviewed
CVE-2025-3079
was published
May 20, 2025
A passback vulnerability which relates to production printers and office multifunction printers.
Moderate
Unreviewed
CVE-2025-3078
was published
May 20, 2025
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers...
Moderate
Unreviewed
CVE-2025-4679
was published
May 16, 2025
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure...
Moderate
Unreviewed
CVE-2025-2772
was published
Apr 23, 2025
Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS
Moderate
CVE-2025-32963
was published
for
github.com/minio/operator
(Go)
Apr 21, 2025
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01...
High
Unreviewed
CVE-2025-28228
was published
Apr 21, 2025
Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password...
Critical
Unreviewed
CVE-2025-22372
was published
Apr 14, 2025
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are...
Low
Unreviewed
CVE-2025-27192
was published
Apr 8, 2025
Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to...
High
Unreviewed
CVE-2025-26628
was published
Apr 8, 2025
The exposure of credentials in the call forwarding configuration module in MeetMe products in...
High
Unreviewed
CVE-2025-2908
was published
Mar 28, 2025
In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns...
Moderate
Unreviewed
CVE-2024-9418
was published
Mar 20, 2025
Jenkins Zoho QEngine Plugin Displays Unmasked API Keys
Low
CVE-2025-30197
was published
for
io.jenkins.plugins:zohoqengine
(Maven)
Mar 19, 2025
An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605...
Critical
Unreviewed
CVE-2025-25650
was published
Mar 17, 2025
Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13...
High
Unreviewed
CVE-2025-2277
was published
Mar 13, 2025
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure...
Moderate
Unreviewed
CVE-2024-47109
was published
Mar 10, 2025
Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability...
High
Unreviewed
CVE-2025-1886
was published
Mar 7, 2025
Insufficiently Protected Credentials
vulnerability in OpenText Identity Manager Advanced Edition...
Critical
Unreviewed
CVE-2024-12799
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014...
Critical
Unreviewed
CVE-2025-27650
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253...
Critical
Unreviewed
CVE-2025-27648
was published
Mar 5, 2025
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote...
High
Unreviewed
CVE-2024-41771
was published
Mar 3, 2025
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote...
High
Unreviewed
CVE-2024-41770
was published
Mar 3, 2025
Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows...
Moderate
Unreviewed
CVE-2024-44754
was published
Feb 28, 2025
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded...
Critical
Unreviewed
CVE-2025-25570
was published
Feb 28, 2025
ProTip!
Advisories are also available from the
GraphQL API