GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
288 advisories
Filter by severity
In affected versions of Octopus Server it is possible to reveal the existence of resources in a...
Moderate
Unreviewed
CVE-2022-2508
was published
Oct 27, 2022
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2025-4166
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can...
Moderate
Unreviewed
CVE-2025-46575
was published
Apr 27, 2025
IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a...
Moderate
Unreviewed
CVE-2025-25045
was published
Apr 24, 2025
Drupal Full Path Disclosure
Moderate
CVE-2024-45440
was published
for
drupal/core
(Composer)
Aug 29, 2024
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution...
Moderate
Unreviewed
CVE-2016-9459
was published
May 13, 2022
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of...
Moderate
Unreviewed
CVE-2017-0885
was published
May 13, 2022
A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to...
Moderate
Unreviewed
CVE-2025-20150
was published
Apr 16, 2025
When importing resources using Web Workers, error messages would distinguish the difference...
Moderate
Unreviewed
CVE-2022-22760
was published
Dec 22, 2022
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP...
Moderate
Unreviewed
CVE-2010-3332
was published
May 13, 2022
An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9...
Moderate
Unreviewed
CVE-2024-11129
was published
Apr 10, 2025
TYPO3 leaks a hash secret in an error message
Moderate
CVE-2009-0815
was published
for
typo3/cms
(Composer)
May 2, 2022
Generation of Error Message Containing Sensitive Information vulnerability in vcita Online...
Moderate
Unreviewed
CVE-2025-32238
was published
Apr 4, 2025
API Platform Core can leak exceptions message that may contain sensitive information
Moderate
CVE-2023-47639
was published
for
api-platform/core
(Composer)
Apr 3, 2025
HCL Traveler generates some error messages that provide detailed information about errors and...
Moderate
Unreviewed
CVE-2025-0279
was published
Apr 4, 2025
Apache Tomcat Leaks Information via Error Message
Moderate
CVE-2002-2008
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 30, 2022
Apache Tomcat Leaks Pathname Information via Error Message
Moderate
CVE-2002-2009
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 30, 2022
An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via...
Moderate
Unreviewed
CVE-2024-30614
was published
Apr 12, 2024
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to...
Moderate
Unreviewed
CVE-2024-6613
was published
Jul 9, 2024
An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7,...
Moderate
Unreviewed
CVE-2024-12380
was published
Mar 13, 2025
Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks...
Moderate
Unreviewed
CVE-2025-2239
was published
Mar 12, 2025
Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical...
Moderate
Unreviewed
CVE-2025-23185
was published
Mar 11, 2025
After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with...
Moderate
Unreviewed
CVE-2025-20002
was published
Mar 5, 2025
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2024-35112
was published
Jan 25, 2025
MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store...
Moderate
Unreviewed
CVE-2025-0941
was published
Feb 26, 2025
ProTip!
Advisories are also available from the
GraphQL API