GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
613 advisories
Filter by severity
Presta Shop vulnerable to email enumeration
Moderate
CVE-2025-51586
was published
for
prestashop/prestashop
(Composer)
Sep 4, 2025
In multiple locations, there is a possible way to access data displayed on the screen due to side...
Moderate
Unreviewed
CVE-2025-48561
was published
Sep 4, 2025
Windows Defender Credential Guard Information Disclosure Vulnerability. This CVE ID is unique...
Moderate
Unreviewed
CVE-2022-34704
was published
Aug 10, 2022
In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset...
Moderate
Unreviewed
CVE-2022-22120
was published
Jan 11, 2022
Liferay Portal User Enumeration Vulnerability via the Create Account Page
Moderate
CVE-2025-43751
was published
for
com.liferay:com.liferay.login.web
(Maven)
Aug 22, 2025
Liferay Portal Enumeration Discrepancy in Calendars
Moderate
CVE-2025-43743
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 19, 2025
Liferay Portal Email Modification Vulnerability via Calendar Portlet
Moderate
CVE-2025-43739
was published
for
com.liferay:com.liferay.calendar.service
(Maven)
Aug 19, 2025
A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this...
Moderate
Unreviewed
CVE-2025-9109
was published
Aug 18, 2025
A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V5.6.0), RUGGEDCOM ROS...
High
Unreviewed
CVE-2021-42016
was published
Mar 9, 2022
OpenBao has a Timing Side-Channel in the Userpass Auth Method
Low
CVE-2025-54999
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
A vulnerability has been found in riscv-boom SonicBOOM up to 2.2.3 and classified as problematic....
Low
Unreviewed
CVE-2025-8774
was published
Aug 9, 2025
The public-facing product registration endpoint server responds
differently depending on whether...
Moderate
Unreviewed
CVE-2025-47872
was published
Aug 8, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
Low
CVE-2025-6011
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Minerva timing attack on P-256 in python-ecdsa
High
CVE-2024-23342
was published
for
ecdsa
(pip)
Jan 22, 2024
Liferay Portal and Liferay DXP User Enumeration Vulnerability
Moderate
CVE-2024-26268
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Moderate
CVE-2024-58262
was published
for
curve25519-dalek
(Rust)
Jun 18, 2024
there is a possible information disclosure due to side channel information disclosure. This could...
Moderate
Unreviewed
CVE-2024-32926
was published
Jun 13, 2024
Timing based private key exposure in Bouncy Castle
Moderate
CVE-2020-15522
was published
for
BouncyCastle
(Maven)
Aug 13, 2021
Observable Differences in Behavior to Error Inputs in Bouncy Castle
Moderate
CVE-2020-26939
was published
for
org.bouncycastle:bc-fips
(Maven)
Apr 22, 2021
An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists...
Moderate
Unreviewed
CVE-2023-38327
was published
Jul 11, 2025
A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the...
Moderate
Unreviewed
CVE-2025-24391
was published
Jul 14, 2025
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
High
CVE-2025-6386
was published
for
lollms
(pip)
Jul 7, 2025
ZITADEL "ignoring unknown usernames" vulnerability
Moderate
CVE-2024-41952
was published
for
github.com/zitadel/zitadel
(Go)
Jul 31, 2024
user enumeration vulnerability in Daily Expense Manager v1.0. To exploit this vulnerability a...
High
Unreviewed
CVE-2025-40732
was published
Jun 30, 2025
Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2...
Moderate
Unreviewed
CVE-2025-6056
was published
Jul 4, 2025
ProTip!
Advisories are also available from the
GraphQL API