GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
214 advisories
Filter by severity
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support....
Moderate
Unreviewed
CVE-2022-0563
was published
Feb 22, 2022
HCL Launch could allow a remote attacker to obtain sensitive information when a detailed...
Moderate
Unreviewed
CVE-2023-45701
was published
Dec 28, 2023
ONTAP Mediator versions prior to 1.7 are susceptible to a
vulnerability that can allow an...
Moderate
Unreviewed
CVE-2023-27319
was published
Dec 22, 2023
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2023-47703
was published
Dec 20, 2023
IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2...
Moderate
Unreviewed
CVE-2023-42013
was published
Dec 20, 2023
Due to improper error handling, a REST API resource could expose a server side error containing...
Moderate
Unreviewed
CVE-2023-6839
was published
Dec 15, 2023
Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user...
Moderate
Unreviewed
CVE-2023-48393
was published
Dec 15, 2023
jupyter-server errors include tracebacks with path information
Moderate
CVE-2023-49080
was published
for
jupyter-server
(pip)
Dec 5, 2023
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a...
Moderate
Unreviewed
CVE-2023-49878
was published
Dec 13, 2023
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2023-43021
was published
Dec 1, 2023
pimcore/admin-ui-classic-bundle Full Path Disclosure via re-export document
Moderate
CVE-2023-47636
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Nov 15, 2023
The response messages received from the eSOMS report generation using certain parameter queries...
Moderate
Unreviewed
CVE-2023-5514
was published
Nov 1, 2023
Apache Superset may expose internal traces on REST API endpoints
Moderate
CVE-2023-39264
was published
for
apache-superset
(pip)
Sep 6, 2023
Jenkins Folders Plugin information disclosure vulnerability
Moderate
CVE-2023-40338
was published
for
org.jenkins-ci.plugins:cloudbees-folder
(Maven)
Aug 16, 2023
User account enumeration in Serenity
Moderate
CVE-2023-31286
was published
for
Serenity.Net.Core
(NuGet)
Apr 27, 2023
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2021-1546
was published
May 24, 2022
ghinstallation returns app JWT in error responses
Moderate
CVE-2022-39304
was published
for
github.com/bradleyfalzon/ghinstallation
(Go)
Dec 19, 2022
Diavante vue-storefront-api and storefront-api disclose stack trace
Moderate
CVE-2020-11883
was published
for
storefront-api
(npm)
May 24, 2022
Eclipse Jetty Server generates error message containing sensitive information
Moderate
CVE-2018-12536
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Oct 19, 2018
Weblate user account enumeration via reset password form
Moderate
CVE-2017-5537
was published
for
weblate
(pip)
May 17, 2022
Insertion of Sensitive Information into Log File in typo3/cms-core
Moderate
CVE-2022-31047
was published
for
typo3/cms
(Composer)
Jun 17, 2022
Kirby CMS vulnerable to user enumeration in the brute force protection
Moderate
CVE-2022-39315
was published
for
getkirby/cms
(Composer)
Oct 18, 2022
Wildfly logs plaintext passwords
Moderate
CVE-2020-25640
was published
for
org.wildfly:wildfly-parent
(Maven)
Feb 15, 2022
Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage...
Moderate
Unreviewed
CVE-2022-34882
was published
Sep 7, 2022
An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts...
Moderate
Unreviewed
CVE-2021-44155
was published
Dec 14, 2021
ProTip!
Advisories are also available from the
GraphQL API