GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,144
NuGet
735
pip
3,947
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
16 advisories
Filter by severity
This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API...
Moderate
Unreviewed
CVE-2025-42604
was published
Apr 23, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and...
Low
Unreviewed
CVE-2025-2469
was published
Apr 10, 2025
Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit allows...
High
Unreviewed
CVE-2025-31001
was published
Apr 1, 2025
A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations...
Moderate
Unreviewed
CVE-2025-2877
was published
Mar 28, 2025
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can...
High
Unreviewed
CVE-2025-1053
was published
Feb 14, 2025
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to...
Moderate
Unreviewed
CVE-2025-20643
was published
Feb 3, 2025
A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when...
Moderate
Unreviewed
CVE-2024-11217
was published
Nov 15, 2024
Apache Airflow: Sensitive configuration values are not masked in the logs by default
High
CVE-2024-45784
was published
for
airflow
(pip)
Nov 15, 2024
Aimeos HTML client may potentially reveal sensitive information in error log
High
CVE-2024-38516
was published
for
aimeos/ai-client-html
(Composer)
Jun 25, 2024
Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the...
Moderate
Unreviewed
CVE-2024-27179
was published
Jun 14, 2024
C300 information leak due to an analysis feature which allows extracting more memory over the...
High
Unreviewed
CVE-2023-5392
was published
Apr 11, 2024
Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message...
Moderate
Unreviewed
CVE-2023-28077
was published
Feb 10, 2024
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an...
High
Unreviewed
CVE-2023-4215
was published
Oct 17, 2023
Vaadin vulnerable to possible information disclosure of class and method names in RPC response
Low
CVE-2023-25500
was published
for
com.vaadin:flow-server
(Maven)
Jun 22, 2023
Dell BSAFE SSL-J when used in debug mode can reveal unnecessary information. An attacker could...
Moderate
Unreviewed
CVE-2022-34364
was published
Feb 10, 2023
Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-19
Moderate
CVE-2021-31412
was published
for
com.vaadin:vaadin-bom
(Maven)
Jun 28, 2021
ProTip!
Advisories are also available from the
GraphQL API