GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
708 advisories
Filter by severity
OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL...
Moderate
Unreviewed
CVE-2026-93982
was published
Sep 19, 2026
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application...
Moderate
Unreviewed
CVE-2026-92758
was published
Sep 17, 2026
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and...
Moderate
Unreviewed
CVE-2026-84527
was published
Sep 14, 2026
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden...
Moderate
Unreviewed
CVE-2026-84525
was published
Sep 14, 2026
A privacy issue was addressed with improved private data redaction for log entries. This issue is...
Moderate
Unreviewed
CVE-2026-84513
was published
Sep 14, 2026
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet...
Moderate
Unreviewed
CVE-2026-73457
was published
Sep 16, 2026
Insertion of sensitive information into log file in the slow query logging feature in Devolutions...
Moderate
Unreviewed
CVE-2026-92237
was published
Sep 15, 2026
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets...
Moderate
Unreviewed
CVE-2026-73467
was published
Sep 15, 2026
On affected platforms running Arista EOS, under certain circumstances user passwordss may be...
Moderate
Unreviewed
CVE-2026-73466
was published
Sep 15, 2026
On affected platforms running Arista EOS, under certain circumstances plaintext private keys may...
Moderate
Unreviewed
CVE-2026-73465
was published
Sep 15, 2026
A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the...
Moderate
Unreviewed
CVE-2026-81320
was published
Sep 15, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-80124
was published
Sep 9, 2026
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log...
Moderate
Unreviewed
CVE-2026-78631
was published
Sep 8, 2026
Insertion of sensitive information into log file in Windows Program Compatibility Assistant...
Moderate
Unreviewed
CVE-2026-68873
was published
Sep 8, 2026
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP...
Moderate
Unreviewed
CVE-2026-86597
was published
Sep 8, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-80056
was published
Sep 7, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM...
Moderate
Unreviewed
CVE-2026-17442
was published
Sep 4, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM...
Moderate
Unreviewed
CVE-2026-16689
was published
Sep 4, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM...
Moderate
Unreviewed
CVE-2026-19649
was published
Sep 4, 2026
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error...
Moderate
Unreviewed
CVE-2026-75573
was published
Aug 27, 2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for...
Moderate
Unreviewed
CVE-2026-75485
was published
Aug 18, 2026
A flaw was found in insights-client. The setDefault() function logs the value of every...
Moderate
Unreviewed
CVE-2026-71845
was published
Aug 11, 2026
A flaw was found in insights-client. When the application receives a non-200 response, it logs...
Moderate
Unreviewed
CVE-2026-71474
was published
Aug 11, 2026
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which...
Moderate
Unreviewed
CVE-2026-21808
was published
Aug 27, 2026
A vulnerability that records guest OS processing credentials in cleartext in a support log on the...
Moderate
Unreviewed
CVE-2026-58070
was published
Aug 27, 2026
ProTip!
Advisories are also available from the
GraphQL API