GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
130 advisories
Filter by severity
nebula-mesh: Operator session tokens stored in plaintext in the database
High
CVE-2026-53603
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
Moderate
CVE-2026-50267
was published
for
Steeltoe.Configuration.Abstractions
(NuGet)
Jul 2, 2026
nebula-mesh's stores enrollment tokens unhashed in SQLite
Moderate
GHSA-ghmh-jhmj-wcmf
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 22, 2026
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
Moderate
CVE-2026-55885
was published
for
getgrav/grav
(Composer)
Jun 18, 2026
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
High
CVE-2026-8596
was published
for
sagemaker
(pip)
May 21, 2026
Electerm's full process.env exposed to renderer via window.pre.env
Moderate
CVE-2026-43942
was published
for
electerm
(npm)
May 8, 2026
Flowise: Bcrypt Password Hash Exposure
Moderate
CVE-2026-8026
was published
for
flowise
(npm)
May 6, 2026
Prometheus Azure AD remote write OAuth client secret exposed via config API
High
CVE-2026-42151
was published
for
github.com/prometheus/prometheus
(Go)
May 5, 2026
Cillium exposes sensitive information included in the cilium-bugtool debug archive
High
CVE-2026-41520
was published
for
github.com/cilium/cilium
(Go)
Apr 25, 2026
TYPO3 CMS Stores Cleartext Password in User Settings Module
High
CVE-2026-6553
was published
for
typo3/cms-backend
(Composer)
Apr 24, 2026
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
Low
CVE-2026-6598
was published
for
langflow
(pip)
Apr 20, 2026
Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request
Moderate
CVE-2026-56270
was published
for
flowise
(npm)
Apr 16, 2026
Directus: Sensitive fields exposed in revision history
Moderate
CVE-2026-39943
was published
for
directus
(npm)
Apr 4, 2026
OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get
Moderate
CVE-2026-41385
was published
for
openclaw
(npm)
Apr 2, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
Critical
CVE-2026-33026
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
High
CVE-2026-34214
was published
for
io.trino:trino-iceberg
(Maven)
Mar 29, 2026
Grafana public dashboards disclose all direct mode datasources
Moderate
CVE-2026-27877
was published
for
github.com/grafana/grafana
(Go)
Mar 27, 2026
Harbor: LDAP password and OIDC secret are not redacted in the audit log
Moderate
GHSA-prh4-vhfh-24mj
was published
for
github.com/goharbor/harbor
(Go)
Mar 26, 2026
AVideo has Plaintext Video Password Storage
Critical
CVE-2026-33867
was published
for
wwbn/avideo
(Composer)
Mar 26, 2026
AVideo has an unauthenticated decrypt oracle leaking any ciphertext
High
CVE-2026-33512
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
Jenkins LoadNinja Plugin stores LoadNinja API keys unencrypted in job config.xml files
Moderate
CVE-2026-33003
was published
for
org.jenkins-ci.plugins:loadninja
(Maven)
Mar 18, 2026
Jenkins LoadNinja Plugin does not mask LoadNinja API keys displayed on the job configuration form
Moderate
CVE-2026-33004
was published
for
org.jenkins-ci.plugins:loadninja
(Maven)
Mar 18, 2026
Rancher doesn't properly sanitize credentials in cluster template answers
Critical
CVE-2021-36783
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
FUXA Unauthenticated Exposure of Plaintext Database Credentials
Critical
CVE-2026-25751
was published
for
fuxa-server
(npm)
Feb 5, 2026
Jenkins's build authorization token is stored and displayed in plain text
Moderate
CVE-2025-67638
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Dec 10, 2025
ProTip!
Advisories are also available from the
GraphQL API