GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,746
Maven
5,000+
npm
4,342
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,209 advisories
Filter by severity
Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
Moderate
CVE-2025-53664
was published
for
com.apica:ApicaLoadtest
(Maven)
Jul 9, 2025
Jenkins Dead Man's Snitch Plugin vulnerability does not mask tokens
Moderate
CVE-2025-53667
was published
for
org.jenkins-ci.plugins:deadmanssnitch
(Maven)
Jul 9, 2025
Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
Moderate
CVE-2025-53665
was published
for
com.apica:ApicaLoadtest
(Maven)
Jul 9, 2025
Jenkins Statistics Gatherer Plugin vulnerability exposes AWS Secret Key
Moderate
CVE-2025-53654
was published
for
org.jenkins.plugins.statistics.gatherer:statistics-gatherer
(Maven)
Jul 9, 2025
Jenkins Aqua Security Scanner Plugin vulnerability exposes scanner tokens
Moderate
CVE-2025-53653
was published
for
org.jenkins-ci.plugins:aqua-security-scanner
(Maven)
Jul 9, 2025
Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messages
Moderate
CVE-2025-53650
was published
for
org.jenkins-ci.plugins:credentials-binding
(Maven)
Jul 9, 2025
Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage
Moderate
Unreviewed
CVE-2025-24508
was published
Jul 7, 2025
A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web...
High
Unreviewed
CVE-2025-34078
was published
Jul 2, 2025
Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers...
Moderate
Unreviewed
CVE-2025-6081
was published
Jul 1, 2025
tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment
High
CVE-2024-49364
was published
for
tiny-secp256k1
(npm)
Jun 30, 2025
An authenticated attacker can reconfigure the target device to use an external service (such as...
Moderate
Unreviewed
CVE-2024-51984
was published
Jun 26, 2025
A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611...
Low
Unreviewed
CVE-2025-6526
was published
Jun 26, 2025
CyberData 011209 Intercom
does not properly store or protect web server admin credentials.
High
Unreviewed
CVE-2025-30183
was published
Jun 10, 2025
Requests vulnerable to .netrc credentials leak via malicious URLs
Moderate
CVE-2024-47081
was published
for
requests
(pip)
Jun 9, 2025
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2025-33079
was published
May 27, 2025
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access...
Moderate
Unreviewed
CVE-2025-2394
was published
May 23, 2025
MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure...
Moderate
Unreviewed
CVE-2025-3480
was published
May 22, 2025
A passback vulnerability which relates to office/small office multifunction printers and laser...
Moderate
Unreviewed
CVE-2025-3079
was published
May 20, 2025
A passback vulnerability which relates to production printers and office multifunction printers.
Moderate
Unreviewed
CVE-2025-3078
was published
May 20, 2025
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers...
Moderate
Unreviewed
CVE-2025-4679
was published
May 16, 2025
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm...
High
Unreviewed
CVE-2025-33093
was published
May 7, 2025
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure...
Moderate
Unreviewed
CVE-2025-2772
was published
Apr 23, 2025
Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS
Moderate
CVE-2025-32963
was published
for
github.com/minio/operator
(Go)
Apr 21, 2025
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01...
High
Unreviewed
CVE-2025-28228
was published
Apr 21, 2025
ProTip!
Advisories are also available from the
GraphQL API