GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
32 advisories
Filter by severity
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64...
Critical
Unreviewed
CVE-2025-14815
was published
Apr 8, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
Critical
CVE-2026-33026
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
AVideo has Plaintext Video Password Storage
Critical
CVE-2026-33867
was published
for
wwbn/avideo
(Composer)
Mar 26, 2026
Rancher doesn't properly sanitize credentials in cluster template answers
Critical
CVE-2021-36783
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
FUXA Unauthenticated Exposure of Plaintext Database Credentials
Critical
CVE-2026-25751
was published
for
fuxa-server
(npm)
Feb 5, 2026
The mobile application was found to contain stored credentials for the network it was developed...
Critical
Unreviewed
CVE-2025-65826
was published
Dec 10, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS...
Critical
Unreviewed
CVE-2025-34206
was published
Sep 19, 2025
Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT...
Critical
Unreviewed
CVE-2025-55443
was published
Aug 26, 2025
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted...
Critical
Unreviewed
CVE-2025-30124
was published
Jul 28, 2025
mySCADA myPRO Manager
stores credentials in cleartext, which could allow an attacker to obtain...
Critical
Unreviewed
CVE-2025-22896
was published
Feb 14, 2025
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB...
Critical
Unreviewed
CVE-2024-51547
was published
Feb 6, 2025
The health endpoint is public so everybody can see a list of all services. It is potentially...
Critical
Unreviewed
CVE-2024-9798
was published
Oct 10, 2024
Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp...
Critical
Unreviewed
CVE-2024-8644
was published
Sep 27, 2024
No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command...
Critical
Unreviewed
CVE-2024-40457
was published
Sep 12, 2024
The decrypted configuration file contains the password in cleartext
which is used to configure...
Critical
Unreviewed
CVE-2024-36497
was published
Jun 24, 2024
Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM ...
Critical
Unreviewed
CVE-2023-41095
was published
Oct 26, 2023
Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation...
Critical
Unreviewed
CVE-2023-2809
was published
Oct 4, 2023
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as...
Critical
Unreviewed
CVE-2023-31069
was published
Sep 11, 2023
Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing...
Critical
Unreviewed
CVE-2023-33373
was published
Aug 4, 2023
Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could...
Critical
Unreviewed
CVE-2022-3089
was published
Feb 13, 2023
A vulnerability has been identified in QMS Automotive (All versions). User credentials are stored...
Critical
Unreviewed
CVE-2022-43958
was published
Nov 8, 2022
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
Critical
Unreviewed
CVE-2020-15332
was published
Sep 30, 2022
Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
Critical
CVE-2021-36782
was published
for
github.com/rancher/rancher
(Go)
Sep 23, 2022
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs,...
Critical
Unreviewed
CVE-2021-29954
was published
May 24, 2022
TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure...
Critical
Unreviewed
CVE-2019-13096
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API