GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,205
Erlang
31
GitHub Actions
19
Go
1,988
Maven
5,000+
npm
3,704
NuGet
661
pip
3,332
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
56 advisories
Filter by severity
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative...
Moderate
Unreviewed
CVE-2024-31200
was published
Jul 31, 2024
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows...
Critical
Unreviewed
CVE-2024-7205
was published
Jul 31, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico
Moderate
CVE-2020-13597
was published
for
github.com/projectcalico/calico
(Go)
Feb 15, 2022
Eclipse Dataspace Components vulnerable to OAuth2 client secret disclosure
Moderate
CVE-2024-4536
was published
for
org.eclipse.edc:connector-core
(Maven)
May 7, 2024
Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCore
Moderate
CVE-2024-32028
was published
for
OpenTelemetry.Instrumentation.AspNetCore
(NuGet)
Apr 12, 2024
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4...
Moderate
Unreviewed
CVE-2023-32275
was published
Oct 12, 2023
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided...
Moderate
Unreviewed
CVE-2022-27779
was published
Jun 3, 2022
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when...
Moderate
Unreviewed
CVE-2019-15580
was published
May 24, 2022
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password"...
Moderate
Unreviewed
CVE-2024-28173
was published
Mar 6, 2024
The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3...
Moderate
Unreviewed
CVE-2024-26270
was published
Feb 20, 2024
Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2,...
Moderate
Unreviewed
CVE-2024-25150
was published
Feb 20, 2024
An information disclosure vulnerability exists in the challenge functionality of instipod...
Moderate
Unreviewed
CVE-2023-49594
was published
Dec 23, 2023
Remote Memory Exposure in mongoose
Moderate
GHSA-r5xw-q988-826m
was published
for
mongoose
(npm)
Sep 1, 2020
Cookies are sent to external images in rendered diff (and server side request forgery)
Critical
CVE-2023-48240
was published
for
org.xwiki.platform:xwiki-platform-diff-xml
(Maven)
Nov 20, 2023
Vaadin vulnerable to possible information disclosure in non visible components.
Moderate
CVE-2023-25499
was published
for
com.vaadin:flow-server
(Maven)
Jun 22, 2023
Remote Memory Exposure in request
Moderate
CVE-2017-16026
was published
for
request
(npm)
Nov 9, 2018
When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and...
Moderate
Unreviewed
CVE-2020-1774
was published
May 24, 2022
keycloak-core discloses system properties
Moderate
CVE-2017-2582
was published
for
org.keycloak:keycloak-core
(Maven)
Oct 18, 2018
Support bundle generated files could contain sensitive information that might be unwanted to be...
Moderate
Unreviewed
CVE-2020-1770
was published
May 24, 2022
A vulnerability was found in the Linux kernel, where accessing a deallocated instance in...
Moderate
Unreviewed
CVE-2020-27784
was published
Sep 2, 2022
Answer vulnerable to Insertion of Sensitive Information Into Sent Data
Moderate
CVE-2023-1975
was published
for
github.com/answerdev/answer
(Go)
Apr 11, 2023
Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
High
CVE-2023-28117
was published
for
sentry-sdk
(pip)
Mar 21, 2023
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the...
Moderate
Unreviewed
CVE-2019-14849
was published
May 24, 2022
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling...
Moderate
Unreviewed
CVE-2020-27748
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API