GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
167 advisories
Filter by severity
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and...
Moderate
Unreviewed
CVE-2023-49515
was published
Jan 17, 2024
Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds
Moderate
CVE-2023-50298
was published
for
org.apache.solr:solr-solrj
(Maven)
Feb 9, 2024
A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties...
Moderate
Unreviewed
CVE-2024-6916
was published
Jul 19, 2024
An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT...
Moderate
Unreviewed
CVE-2024-5288
was published
Aug 27, 2024
Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified...
Moderate
Unreviewed
CVE-2024-25655
was published
Mar 18, 2024
In the goTenna Pro ATAK Plugin application, the encryption keys are
stored along with a static...
Moderate
Unreviewed
CVE-2024-43694
was published
Sep 26, 2024
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic...
Moderate
Unreviewed
CVE-2024-33004
was published
May 14, 2024
In the goTenna Pro application, the encryption keys are stored along with a static IV on the...
Moderate
Unreviewed
CVE-2024-47122
was published
Sep 26, 2024
In the goTenna Pro ATAK Plugin application, the encryption keys are
stored along with a static...
Moderate
Unreviewed
CVE-2024-45374
was published
Sep 26, 2024
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User...
Moderate
Unreviewed
CVE-2024-21258
was published
Oct 15, 2024
scikit-learn sensitive data leakage vulnerability
Moderate
CVE-2024-5206
was published
for
scikit-learn
(pip)
Jun 6, 2024
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator...
Moderate
Unreviewed
CVE-2023-37439
was published
Aug 22, 2023
vCenter Server contains a partial information disclosure vulnerability. A malicious actor with...
Moderate
Unreviewed
CVE-2023-34056
was published
Oct 25, 2023
A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the...
Moderate
Unreviewed
CVE-2023-41723
was published
Nov 14, 2023
This issue was addressed with improved redaction of sensitive information. This issue is fixed in...
Moderate
Unreviewed
CVE-2024-44257
was published
Oct 29, 2024
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-44216
was published
Oct 29, 2024
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.1 and...
Moderate
Unreviewed
CVE-2024-44263
was published
Oct 28, 2024
HCL Launch could disclose sensitive information if a manual edit of a configuration file has been...
Moderate
Unreviewed
CVE-2023-23348
was published
Jul 10, 2023
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET...
Moderate
Unreviewed
CVE-2022-30361
was published
Oct 25, 2024
A lock screen issue was addressed with improved state management. This issue is fixed in watchOS...
Moderate
Unreviewed
CVE-2024-40813
was published
Jul 30, 2024
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-44175
was published
Oct 28, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An...
Moderate
Unreviewed
CVE-2024-44174
was published
Oct 28, 2024
In flashc, there is a possible information disclosure due to an uncaught exception. This could...
Moderate
Unreviewed
CVE-2024-20050
was published
Apr 1, 2024
When browsing private tabs, some data related to location history or webpage thumbnails could be...
Moderate
Unreviewed
CVE-2024-38312
was published
Jun 13, 2024
A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the...
Moderate
Unreviewed
CVE-2024-25360
was published
Feb 12, 2024
ProTip!
Advisories are also available from the
GraphQL API