GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
743 advisories
Filter by severity
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on...
Moderate
Unreviewed
CVE-2026-34490
was published
Jul 31, 2026
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote...
Moderate
Unreviewed
CVE-2026-59327
was published
Jul 30, 2026
The web management interface in
Tycon Systems TPDIN-Monitor-WEB2
stores and displays system...
Moderate
Unreviewed
CVE-2026-55985
was published
Jul 25, 2026
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell...
Moderate
Unreviewed
CVE-2026-16802
was published
Jul 24, 2026
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to...
High
Unreviewed
CVE-2024-58023
was published
Jul 23, 2026
n8n: Google Service Account Private Key Exposed in JWT Header
Moderate
CVE-2026-65599
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header
Moderate
GHSA-mhvh-gwhr-76pw
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
nebula-mesh: Operator session tokens stored in plaintext in the database
High
CVE-2026-53603
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
ActiveMQ Artemis has Insufficiently Protected Credentials
Moderate
CVE-2020-10727
was published
for
org.apache.activemq:artemis-commons
(Maven)
May 24, 2022
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
Critical
CVE-2026-33026
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct...
High
Unreviewed
CVE-2021-42642
was published
Feb 9, 2022
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the...
Moderate
Unreviewed
CVE-2023-25263
was published
Mar 27, 2023
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and...
High
Unreviewed
CVE-2021-36460
was published
Apr 26, 2022
The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV...
High
Unreviewed
CVE-2021-28937
was published
May 24, 2022
Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does...
Moderate
Unreviewed
CVE-2026-8804
was published
Jul 3, 2026
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
Moderate
CVE-2026-50267
was published
for
Steeltoe.Configuration.Abstractions
(NuGet)
Jul 2, 2026
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext...
High
Unreviewed
CVE-2026-43824
was published
May 2, 2026
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted...
Moderate
Unreviewed
CVE-2026-7163
was published
Apr 30, 2026
Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr...
Moderate
Unreviewed
CVE-2026-38571
was published
Jun 27, 2026
Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the...
Moderate
Unreviewed
CVE-2026-57287
was published
Jun 24, 2026
Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request
Moderate
CVE-2026-56270
was published
for
flowise
(npm)
Apr 16, 2026
nebula-mesh's stores enrollment tokens unhashed in SQLite
Moderate
GHSA-ghmh-jhmj-wcmf
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 22, 2026
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
Moderate
CVE-2026-55885
was published
for
getgrav/grav
(Composer)
Jun 18, 2026
Improper access control in the ticketing integration settings in Devolutions Server allows an...
Moderate
Unreviewed
CVE-2026-10786
was published
Jun 8, 2026
Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies...
Moderate
Unreviewed
CVE-2025-10464
was published
Feb 9, 2026
ProTip!
Advisories are also available from the
GraphQL API