Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

520 advisories

Loading
Sensitive customer information is stored in the device without encryption. Unknown Unreviewed
CVE-2024-38283 was published Jun 13, 2024
silverstripe/framework users inadvertently passing sensitive data to LoginAttempt Moderate
GHSA-ph62-fv59-vf9h was published for silverstripe/framework (Composer) May 27, 2024
NASA AIT-Core uses unencrypted channels to exchange data over the network High
CVE-2024-35061 was published for ait-core (pip) May 21, 2024
Vulnerable data in transit in GE HealthCare EchoPAC products Moderate Unreviewed
CVE-2024-27106 was published May 14, 2024
IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive... Moderate Unreviewed
CVE-2023-35888 was published Mar 20, 2024
Unencrypted traffic between nodes when using WireGuard and L7 policies Moderate
CVE-2024-28250 was published for github.com/cilium/cilium (Go) Mar 18, 2024
giorio94 Credited to giorio94, brb, and jschwinger233 brb brb
jschwinger233 jschwinger233
Unencrypted traffic between nodes when using IPsec and L7 policies Moderate
CVE-2024-28249 was published for github.com/cilium/cilium (Go) Mar 18, 2024
giorio94 Credited to giorio94, jschwinger233, and julianwiedmann jschwinger233 jschwinger233
julianwiedmann julianwiedmann
Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI. Critical Unreviewed
CVE-2024-29151 was published Mar 18, 2024
Unencrypted traffic between pods when using Wireguard and an external kvstore Moderate
CVE-2024-25631 was published for github.com/cilium/cilium (Go) Feb 20, 2024
gandro Credited to gandro and giorio94 giorio94 giorio94
Unencrypted ingress/health traffic when using Wireguard transparent encryption Moderate
CVE-2024-25630 was published for github.com/cilium/cilium (Go) Feb 20, 2024
gandro Credited to gandro and giorio94 giorio94 giorio94
1Panel set-cookie is missing the Secure keyword Low
CVE-2024-24768 was published for github.com/1Panel-dev/1Panel (Go) Feb 5, 2024
anonymous-nlp-student Credited to anonymous-nlp-student
Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow... Moderate Unreviewed
CVE-2023-50126 was published Jan 11, 2024
Google Nest WiFi Pro root code-execution & user-data compromise Critical Unreviewed
CVE-2023-6339 was published Jan 3, 2024
ProTip! Advisories are also available from the GraphQL API