GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the...
Moderate
Unreviewed
CVE-2026-0809
was published
Mar 12, 2026
A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The...
Moderate
Unreviewed
CVE-2024-52334
was published
Feb 10, 2026
An attacker with access to the project file could use the exposed
credentials to impersonate...
Moderate
Unreviewed
CVE-2025-67652
was published
Jan 23, 2026
The credentials required to access the device's web server are sent in base64 within the HTTP...
Moderate
Unreviewed
CVE-2026-22543
was published
Jan 7, 2026
Strapi Password Hashing is Missing Maximum Password Length Validation
Moderate
CVE-2025-25298
was published
for
@strapi/core
(npm)
Oct 16, 2025
The credentials required to access the device's web server are sent in base64 within the HTTP...
Moderate
Unreviewed
CVE-2025-11155
was published
Sep 29, 2025
Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this...
Moderate
Unreviewed
CVE-2025-26401
was published
Apr 4, 2025
SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an...
Moderate
Unreviewed
CVE-2025-2862
was published
Mar 28, 2025
Advantech ADAM-5630 shares user credentials plain text between the device and the user source...
Moderate
Unreviewed
CVE-2024-34542
was published
Sep 27, 2024
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64...
Moderate
Unreviewed
CVE-2024-37187
was published
Sep 27, 2024
ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords...
Moderate
Unreviewed
CVE-2024-34113
was published
Jun 13, 2024
A weak encoding is used to transmit credentials for WS203VICM.
Moderate
Unreviewed
CVE-2024-23492
was published
Mar 1, 2024
Lantronix XPort sends weakly encoded credentials within web request headers.
Moderate
Unreviewed
CVE-2023-7237
was published
Jan 24, 2024
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure...
Moderate
Unreviewed
CVE-2023-43776
was published
Oct 17, 2023
Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for...
Moderate
Unreviewed
CVE-2023-22271
was published
Mar 22, 2023
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A...
Moderate
Unreviewed
CVE-2022-34445
was published
Feb 11, 2023
This vulnerability allows remote attackers to disclose sensitive information on affected...
Moderate
Unreviewed
CVE-2020-10919
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API