GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
67 advisories
Filter by severity
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private...
High
Unreviewed
CVE-2024-8474
was published
Jan 6, 2025
SixLabors.ImageSharp vulnerable to data leakage
Moderate
CVE-2024-32036
was published
for
SixLabors.ImageSharp
(NuGet)
Apr 15, 2024
Apache StreamPark: Information leakage vulnerability
Moderate
CVE-2024-29120
was published
for
org.apache.streampark:streampark
(Maven)
Jul 17, 2024
A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks...
Moderate
Unreviewed
CVE-2023-1637
was published
Mar 28, 2023
A vulnerability in the implementation of the internal system processes of Cisco APIC could allow...
Moderate
Unreviewed
CVE-2025-20118
was published
Feb 26, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
CVE-2025-27221
was published
for
uri
(RubyGems)
Mar 3, 2025
In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to...
High
Unreviewed
CVE-2022-3460
was published
Jan 3, 2023
Kubernetes did not effectively clear service account credentials
High
CVE-2019-11243
was published
for
k8s.io/kubernetes
(Go)
May 24, 2022
Wasmtime may have data leakage between instances in the pooling allocator
High
CVE-2022-39393
was published
for
wasmtime
(Rust)
Nov 10, 2022
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called...
High
Unreviewed
CVE-2018-6337
was published
May 13, 2022
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript through 10.05.0 lacks...
Low
Unreviewed
CVE-2025-48708
was published
May 23, 2025
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2025-1759
was published
Aug 18, 2025
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which...
Moderate
Unreviewed
CVE-2024-7698
was published
Sep 10, 2024
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0...
Moderate
Unreviewed
CVE-2025-33013
was published
Jul 25, 2025
Contao can disclose sensitive information in the news module
Moderate
CVE-2025-57757
was published
for
contao/contao
(Composer)
Aug 28, 2025
XWiki PDF export jobs store sensitive cookies unencrypted in job statuses
Moderate
CVE-2025-58049
was published
for
org.xwiki.platform:xwiki-platform-export-pdf-api
(Maven)
Aug 28, 2025
Improper removal of sensitive information before storage or transfer in AMD Crash Defender could...
Low
Unreviewed
CVE-2025-0011
was published
Sep 6, 2025
ProTip!
Advisories are also available from the
GraphQL API