GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,782
NuGet
683
pip
3,460
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
557 advisories
Filter by severity
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from...
High
Unreviewed
CVE-2024-36558
was published
Feb 6, 2025
Keycloak on Quarkus CLI option for encrypted JGroups ignored
Moderate
CVE-2024-10973
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Feb 5, 2025
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or...
Moderate
Unreviewed
CVE-2024-43187
was published
Feb 4, 2025
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear...
Moderate
Unreviewed
CVE-2023-35017
was published
Jan 29, 2025
A Credential Exposure Vulnerability exists in the above-mentioned product and version. The...
High
Unreviewed
CVE-2025-0631
was published
Jan 28, 2025
EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added,...
Moderate
Unreviewed
CVE-2025-0432
was published
Jan 28, 2025
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication...
Moderate
Unreviewed
CVE-2024-28786
was published
Jan 28, 2025
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
expose clear text...
Moderate
Unreviewed
CVE-2024-26155
was published
Jan 17, 2025
The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over...
Moderate
Unreviewed
CVE-2024-48121
was published
Jan 15, 2025
A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA...
Moderate
Unreviewed
CVE-2024-45102
was published
Jan 15, 2025
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. ...
Low
Unreviewed
CVE-2024-42181
was published
Jan 13, 2025
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive...
Low
Unreviewed
CVE-2024-11946
was published
Dec 30, 2024
IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms...
Moderate
Unreviewed
CVE-2021-39081
was published
Dec 19, 2024
Duplicate Advisory: Keycloak vulnerable to Cleartext Transmission of Sensitive Information
Moderate
GHSA-6mpx-pmgp-ww49
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Dec 18, 2024
•
withdrawn
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote...
Low
Unreviewed
CVE-2024-49820
was published
Dec 17, 2024
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote...
Moderate
Unreviewed
CVE-2024-49819
was published
Dec 17, 2024
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions...
Moderate
Unreviewed
CVE-2024-53246
was published
Dec 10, 2024
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information...
Low
Unreviewed
CVE-2024-47577
was published
Dec 10, 2024
Web browser interface may manipulate application username/password in clear text or Base64...
High
Unreviewed
CVE-2024-6515
was published
Dec 5, 2024
IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2021-29892
was published
Dec 3, 2024
Improper data protection on the ventilator's serial interface could allow an attacker to send and...
Critical
Unreviewed
CVE-2024-9834
was published
Nov 14, 2024
Cleartext transmission of sensitive information for some BigDL software maintained by Intel(R)...
Moderate
Unreviewed
CVE-2024-28169
was published
Nov 13, 2024
Moodle authorization headers preserved between "emulated redirects"
Low
CVE-2024-43432
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform...
High
Unreviewed
CVE-2024-50634
was published
Nov 8, 2024
A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive...
Moderate
Unreviewed
CVE-2024-32946
was published
Oct 30, 2024
ProTip!
Advisories are also available from the
GraphQL API