GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
238 advisories
Filter by severity
Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows...
High
Unreviewed
CVE-2026-19051
was published
Sep 4, 2026
OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An...
Moderate
Unreviewed
CVE-2026-15933
was published
Sep 3, 2026
HDD password plaintext is stored in a UEFI variable.
High
Unreviewed
CVE-2021-38489
was published
Sep 3, 2026
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in...
High
Unreviewed
CVE-2026-82453
was published
Aug 29, 2026
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database
...
High
Unreviewed
CVE-2026-50641
was published
Jul 29, 2026
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw...
Moderate
Unreviewed
CVE-2026-41874
was published
Jul 28, 2026
Weintek cMT3092X HMI stores user account passwords in plaintext.
High
Unreviewed
CVE-2026-61886
was published
Jul 25, 2026
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password...
High
Unreviewed
CVE-2026-40430
was published
Jul 24, 2026
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability...
Low
Unreviewed
CVE-2026-44187
was published
Jul 22, 2026
Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all...
Moderate
Unreviewed
CVE-2026-14867
was published
Jul 7, 2026
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
Low
CVE-2026-50268
was published
for
Steeltoe.Configuration.Encryption
(NuGet)
Jul 2, 2026
Lemur user-update path stores plaintext passwords
Moderate
CVE-2026-55164
was published
for
lemur
(pip)
Jun 25, 2026
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on...
Moderate
Unreviewed
CVE-2026-57302
was published
Jun 24, 2026
motionEye: Authentication possible via password hash
Critical
CVE-2026-46488
was published
for
motioneye
(pip)
Jun 22, 2026
update_disk_psu_baseline.sh requires password in plain text
High
Unreviewed
CVE-2024-39575
was published
Jun 16, 2026
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be...
Moderate
Unreviewed
CVE-2024-45636
was published
Jun 11, 2026
GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext...
Moderate
Unreviewed
CVE-2026-36174
was published
Jun 4, 2026
Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows...
High
Unreviewed
CVE-2018-25396
was published
May 29, 2026
Prometheus Azure AD remote write OAuth client secret exposed via config API
High
CVE-2026-42151
was published
for
github.com/prometheus/prometheus
(Go)
May 5, 2026
Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve...
Moderate
Unreviewed
CVE-2026-6500
was published
May 4, 2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text...
Moderate
Unreviewed
CVE-2025-36335
was published
May 1, 2026
Langflow has an Information Leak through Incomplete API Key Redaction
Low
CVE-2026-6597
was published
for
langflow
(pip)
Apr 20, 2026
Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. ...
Critical
Unreviewed
CVE-2025-15624
was published
Apr 17, 2026
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684...
High
Unreviewed
CVE-2021-47961
was published
Apr 10, 2026
OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an...
Critical
Unreviewed
CVE-2026-35556
was published
Apr 9, 2026
ProTip!
Advisories are also available from the
GraphQL API