GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
53 advisories
Filter by severity
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role,...
Critical
Unreviewed
CVE-2026-66780
was published
Aug 18, 2026
Various sensitive information such as passwords and charging card UIDs are written to log files.
Critical
Unreviewed
CVE-2026-22098
was published
Jul 13, 2026
The acer_cgi.log file in the device firmware is accessible without authentication via the web...
Critical
Unreviewed
CVE-2026-49200
was published
May 29, 2026
An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with...
Critical
Unreviewed
CVE-2024-6060
was published
Jun 26, 2024
An issue was discovered in BMC Control-M 9.0.21.300. When Control-M Server has a database...
Critical
Unreviewed
CVE-2025-48709
was published
Aug 7, 2025
The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Critical
Unreviewed
CVE-2025-11008
was published
Nov 4, 2025
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging...
Critical
Unreviewed
CVE-2025-34183
was published
Sep 16, 2025
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an...
Critical
Unreviewed
CVE-2017-6709
was published
May 13, 2022
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log...
Critical
Unreviewed
CVE-2017-8075
was published
May 17, 2022
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log...
Critical
Unreviewed
CVE-2017-8074
was published
May 17, 2022
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive...
Critical
Unreviewed
CVE-2025-22275
was published
Jan 3, 2025
django-anymail Includes Sensitive Information in Log Files
Critical
CVE-2018-1000089
was published
for
django-anymail
(pip)
May 14, 2022
GitHub personal access token leaking into temporary EasyBuild (debug) logs
Critical
CVE-2020-5262
was published
for
easybuild-framework
(pip)
Mar 19, 2020
Ansible Insertion of Sensitive Information into Log File vulnerability
Critical
CVE-2017-7550
was published
for
ansible
(pip)
May 13, 2022
OpenStack Nova logs sensitive context from notification exceptions
Critical
CVE-2017-7214
was published
for
nova
(pip)
May 14, 2022
@valtimo/components exposes access token to form.io
Critical
CVE-2024-34706
was published
for
@valtimo/components
(npm)
May 13, 2024
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log...
Critical
Unreviewed
CVE-2019-17395
was published
May 24, 2022
In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the...
Critical
Unreviewed
CVE-2019-17398
was published
May 24, 2022
In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in...
Critical
Unreviewed
CVE-2019-17396
was published
May 24, 2022
In the Orbitz application 19.31.1 for Android, the username and password are stored in the log...
Critical
Unreviewed
CVE-2019-17355
was published
May 24, 2022
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are...
Critical
Unreviewed
CVE-2019-17394
was published
May 24, 2022
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade,...
Critical
Unreviewed
CVE-2019-15294
was published
May 24, 2022
Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage...
Critical
Unreviewed
CVE-2022-36407
was published
Mar 25, 2024
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion...
Critical
Unreviewed
CVE-2023-36649
was published
Dec 12, 2023
ProTip!
Advisories are also available from the
GraphQL API