GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
386 advisories
Filter by severity
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
Moderate
CVE-2026-55860
was published
for
org.mariadb:r2dbc-mariadb
(Maven)
Aug 28, 2026
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55857
was published
for
org.mariadb.jdbc:mariadb-java-client
(Maven)
Aug 28, 2026
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
Moderate
CVE-2026-55854
was published
for
mariadb
(npm)
Aug 28, 2026
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks...
Moderate
Unreviewed
CVE-2026-19854
was published
Aug 27, 2026
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing...
Moderate
Unreviewed
CVE-2026-79779
was published
Aug 25, 2026
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in...
Moderate
Unreviewed
CVE-2026-77131
was published
Aug 25, 2026
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During...
Moderate
Unreviewed
CVE-2026-19683
was published
Aug 20, 2026
The HTTPPasswordMgr class in the urllib.request module, along with its subclasses...
Moderate
Unreviewed
CVE-2026-15806
was published
Aug 18, 2026
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
Moderate
GHSA-h4mf-4v27-hggj
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
Moderate
GHSA-8mxv-9xhp-86h4
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could...
Moderate
Unreviewed
CVE-2026-20294
was published
Aug 5, 2026
This issue was addressed by using HTTPS when sending information over the network. This issue is...
Moderate
Unreviewed
CVE-2026-64742
was published
Jul 27, 2026
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext...
Moderate
Unreviewed
CVE-2026-3182
was published
Jul 21, 2026
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock...
Moderate
Unreviewed
CVE-2026-34346
was published
Jul 14, 2026
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
Moderate
CVE-2026-53624
was published
for
github.com/gofiber/fiber
(Go)
Jul 6, 2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could...
Moderate
Unreviewed
CVE-2025-36336
was published
Jun 30, 2026
IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch-1 transmits data in clear...
Moderate
Unreviewed
CVE-2025-12530
was published
Jun 30, 2026
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
Moderate
CVE-2026-55568
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
Moderate
CVE-2026-48022
was published
for
@hapi/wreck
(npm)
Jun 11, 2026
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over...
Moderate
Unreviewed
CVE-2026-36610
was published
Jun 3, 2026
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client...
Moderate
Unreviewed
CVE-2023-52951
was published
Jun 3, 2026
Cleartext transmission of sensitive information vulnerability in Export Key functionality in...
Moderate
Unreviewed
CVE-2024-47269
was published
May 27, 2026
Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of...
Moderate
Unreviewed
CVE-2026-38740
was published
May 14, 2026
HCL AION is affected by a vulnerability where backend service details may be transmitted over...
Moderate
Unreviewed
CVE-2025-62311
was published
May 14, 2026
HCL AION is affected by a vulnerability where encryption is not enforced for certain data...
Moderate
Unreviewed
CVE-2025-62310
was published
May 14, 2026
ProTip!
Advisories are also available from the
GraphQL API