Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

238 advisories

Loading
HDD password plaintext is stored in a UEFI variable. High Unreviewed
CVE-2021-38489 was published Sep 3, 2026
Weintek cMT3092X HMI stores user account passwords in plaintext. High Unreviewed
CVE-2026-61886 was published Jul 25, 2026
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding Low
CVE-2026-50268 was published for Steeltoe.Configuration.Encryption (NuGet) Jul 2, 2026
Lemur user-update path stores plaintext passwords Moderate
CVE-2026-55164 was published for lemur (pip) Jun 25, 2026
sour-exploit Credited to sour-exploit
motionEye: Authentication possible via password hash Critical
CVE-2026-46488 was published for motioneye (pip) Jun 22, 2026
FireByteApplications Credited to FireByteApplications, 0xLynk, dimashn04, C4spr0x1A, sighnwaive, MichaIng, Marijn0, and zagrim 0xLynk 0xLynk
dimashn04 dimashn04 C4spr0x1A C4spr0x1A sighnwaive sighnwaive MichaIng MichaIng Marijn0 Marijn0 zagrim zagrim
update_disk_psu_baseline.sh requires password in plain text High Unreviewed
CVE-2024-39575 was published Jun 16, 2026
Prometheus Azure AD remote write OAuth client secret exposed via config API High
CVE-2026-42151 was published for github.com/prometheus/prometheus (Go) May 5, 2026
brettgervasoni Credited to brettgervasoni and noren95 noren95 noren95
Langflow has an Information Leak through Incomplete API Key Redaction Low
CVE-2026-6597 was published for langflow (pip) Apr 20, 2026
ProTip! Advisories are also available from the GraphQL API