GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
718 advisories
Filter by severity
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76374
was published
Aug 20, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with...
Moderate
Unreviewed
CVE-2026-76375
was published
Aug 20, 2026
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an...
Moderate
Unreviewed
CVE-2019-1961
was published
May 24, 2022
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could...
Moderate
Unreviewed
CVE-2019-1953
was published
May 24, 2022
A vulnerability that records guest OS processing credentials in cleartext in a support log on the...
Moderate
Unreviewed
CVE-2026-58070
was published
Aug 27, 2026
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which...
Moderate
Unreviewed
CVE-2026-21808
was published
Aug 27, 2026
A flaw was found in insights-client. The setDefault() function logs the value of every...
Moderate
Unreviewed
CVE-2026-71845
was published
Aug 11, 2026
A flaw was found in insights-client. When the application receives a non-200 response, it logs...
Moderate
Unreviewed
CVE-2026-71474
was published
Aug 11, 2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for...
Moderate
Unreviewed
CVE-2026-75485
was published
Aug 18, 2026
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error...
Moderate
Unreviewed
CVE-2026-75573
was published
Aug 27, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM...
Moderate
Unreviewed
CVE-2026-19649
was published
Sep 4, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM...
Moderate
Unreviewed
CVE-2026-16689
was published
Sep 4, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM...
Moderate
Unreviewed
CVE-2026-17442
was published
Sep 4, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-80056
was published
Sep 7, 2026
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP...
Moderate
Unreviewed
CVE-2026-86597
was published
Sep 8, 2026
Insertion of sensitive information into log file in Windows Program Compatibility Assistant...
Moderate
Unreviewed
CVE-2026-68873
was published
Sep 8, 2026
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log...
Moderate
Unreviewed
CVE-2026-78631
was published
Sep 8, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-80124
was published
Sep 9, 2026
A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the...
Moderate
Unreviewed
CVE-2026-81320
was published
Sep 15, 2026
On affected platforms running Arista EOS, under certain circumstances plaintext private keys may...
Moderate
Unreviewed
CVE-2026-73465
was published
Sep 15, 2026
On affected platforms running Arista EOS, under certain circumstances user passwordss may be...
Moderate
Unreviewed
CVE-2026-73466
was published
Sep 15, 2026
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets...
Moderate
Unreviewed
CVE-2026-73467
was published
Sep 15, 2026
Insertion of sensitive information into log file in the slow query logging feature in Devolutions...
Moderate
Unreviewed
CVE-2026-92237
was published
Sep 15, 2026
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet...
Moderate
Unreviewed
CVE-2026-73457
was published
Sep 16, 2026
ProTip!
Advisories are also available from the
GraphQL API