GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
46 advisories
Filter by severity
On Windows systems, the Arc configuration files resulted to be world-readable.
This can lead...
Moderate
Unreviewed
CVE-2023-5937
was published
May 15, 2024
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a...
Moderate
Unreviewed
CVE-2024-9671
was published
Oct 9, 2024
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with...
Moderate
Unreviewed
CVE-2024-47580
was published
Dec 10, 2024
An attacker authenticated as an administrator can use an exposed webservice to upload or download...
Moderate
Unreviewed
CVE-2024-47579
was published
Dec 10, 2024
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in...
Moderate
Unreviewed
CVE-2025-22306
was published
Jan 7, 2025
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.1...
Moderate
Unreviewed
CVE-2025-0194
was published
Jan 8, 2025
During MegaBIP installation process, a user is encouraged to change a default path to...
Moderate
Unreviewed
CVE-2024-6880
was published
Jan 10, 2025
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in...
Moderate
Unreviewed
CVE-2025-22773
was published
Jan 15, 2025
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in...
Moderate
Unreviewed
CVE-2025-24689
was published
Jan 27, 2025
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade...
Moderate
Unreviewed
CVE-2022-43933
was published
Feb 4, 2025
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in...
Moderate
Unreviewed
CVE-2025-22633
was published
Feb 24, 2025
Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record
Moderate
CVE-2025-27017
was published
for
org.apache.nifi:nifi-mongodb-services
(Maven)
Mar 12, 2025
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via...
Moderate
Unreviewed
CVE-2025-25586
was published
Mar 18, 2025
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in...
Moderate
Unreviewed
CVE-2025-31550
was published
Apr 1, 2025
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in...
Moderate
Unreviewed
CVE-2025-31558
was published
Apr 3, 2025
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in...
Moderate
Unreviewed
CVE-2025-31421
was published
Apr 4, 2025
In devinfo, there is a possible information disclosure due to a missing SELinux policy. This...
Moderate
Unreviewed
CVE-2025-20665
was published
May 5, 2025
An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS...
Moderate
Unreviewed
CVE-2024-51977
was published
Jun 26, 2025
By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the...
Moderate
Unreviewed
CVE-2025-8452
was published
Aug 12, 2025
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
Moderate
Unreviewed
CVE-2025-57734
was published
Aug 20, 2025
Jenkins Git client Plugin file system information disclosure vulnerability
Moderate
CVE-2025-58458
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Sep 3, 2025
ProTip!
Advisories are also available from the
GraphQL API