GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,950
Maven
5,000+
npm
4,596
NuGet
787
pip
4,301
Pub
12
RubyGems
982
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
29 advisories
Filter by severity
An attacker with access to the project file could use the exposed
credentials to impersonate...
Moderate
Unreviewed
CVE-2025-67652
was published
Jan 23, 2026
The credentials required to access the device's web server are sent in base64 within the HTTP...
Moderate
Unreviewed
CVE-2026-22543
was published
Jan 7, 2026
Strapi Password Hashing is Missing Maximum Password Length Validation
Moderate
CVE-2025-25298
was published
for
@strapi/core
(npm)
Oct 16, 2025
The credentials required to access the device's web server are sent in base64 within the HTTP...
Moderate
Unreviewed
CVE-2025-11155
was published
Sep 29, 2025
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6...
Critical
Unreviewed
CVE-2025-31229
was published
Jul 30, 2025
Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this...
Moderate
Unreviewed
CVE-2025-26401
was published
Apr 4, 2025
SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an...
Moderate
Unreviewed
CVE-2025-2862
was published
Mar 28, 2025
Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward...
High
Unreviewed
CVE-2024-7407
was published
Mar 28, 2025
An unauthenticated local attacker can decrypt the devices config file and therefore compromise...
High
Unreviewed
CVE-2024-45273
was published
Oct 15, 2024
The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain...
High
Unreviewed
CVE-2024-8455
was published
Sep 30, 2024
Advantech ADAM-5630 shares user credentials plain text between the device and the user source...
Moderate
Unreviewed
CVE-2024-34542
was published
Sep 27, 2024
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64...
Moderate
Unreviewed
CVE-2024-37187
was published
Sep 27, 2024
ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords...
Moderate
Unreviewed
CVE-2024-34113
was published
Jun 13, 2024
An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via...
High
Unreviewed
CVE-2024-28270
was published
Apr 8, 2024
A weak encoding is used to transmit credentials for WS203VICM.
Moderate
Unreviewed
CVE-2024-23492
was published
Mar 1, 2024
Lantronix XPort sends weakly encoded credentials within web request headers.
Moderate
Unreviewed
CVE-2023-7237
was published
Jan 24, 2024
A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1...
High
Unreviewed
CVE-2024-0556
was published
Jan 16, 2024
Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 ...
Low
Unreviewed
CVE-2023-28896
was published
Dec 1, 2023
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure...
Moderate
Unreviewed
CVE-2023-43776
was published
Oct 17, 2023
Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27...
High
Unreviewed
CVE-2023-0525
was published
Aug 4, 2023
Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for...
Moderate
Unreviewed
CVE-2023-22271
was published
Mar 22, 2023
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A...
Moderate
Unreviewed
CVE-2022-34445
was published
Feb 11, 2023
SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on...
High
Unreviewed
CVE-2023-0356
was published
Jan 26, 2023
An unauthorized user with network access and the decryption key could decrypt sensitive data,...
High
Unreviewed
CVE-2022-38469
was published
Jan 18, 2023
This vulnerability allows remote attackers to disclose sensitive information on affected...
Moderate
Unreviewed
CVE-2020-10919
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API