GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,479
Maven
5,000+
npm
5,000+
NuGet
886
pip
4,740
Pub
13
RubyGems
1,031
Rust
1,225
Swift
53
Unreviewed advisories
All unreviewed
5,000+
89 advisories
Filter by severity
Sentry vulnerable to leaking superuser cleartext password in logs
High
CVE-2024-32474
was published
for
sentry
(pip)
Apr 18, 2024
Keycloak vulnerable to log Injection during WebAuthn authentication or registration
Moderate
CVE-2023-6484
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 17, 2024
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM...
Moderate
Unreviewed
CVE-2024-22356
was published
Mar 26, 2024
Potential log injection in reset user endpoint in CKAN
Moderate
CVE-2024-27097
was published
for
ckan
(pip)
Mar 13, 2024
Ansible-core information disclosure flaw
Moderate
CVE-2024-0690
was published
for
ansible-core
(pip)
Feb 6, 2024
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate...
Moderate
Unreviewed
CVE-2023-38020
was published
Feb 2, 2024
A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1...
Moderate
Unreviewed
CVE-2024-0987
was published
Jan 29, 2024
Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed...
Low
Unreviewed
CVE-2024-22229
was published
Jan 24, 2024
OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected...
Moderate
Unreviewed
CVE-2023-7234
was published
Jan 16, 2024
An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7...
Moderate
Unreviewed
CVE-2023-46713
was published
Dec 13, 2023
YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated...
High
Unreviewed
CVE-2023-6002
was published
Nov 8, 2023
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The...
Critical
Unreviewed
CVE-2023-46322
was published
Oct 23, 2023
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs....
Critical
Unreviewed
CVE-2023-46321
was published
Oct 23, 2023
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in...
Moderate
Unreviewed
CVE-2023-4065
was published
Sep 27, 2023
In Splunk IT Service Intelligence (ITSI) versions below 4.13.3 or 4.15.3, a malicious actor can...
High
Unreviewed
CVE-2023-4571
was published
Aug 30, 2023
Splunk SOAR versions 6.0.2 and earlier are indirectly affected by a potential vulnerability...
High
Unreviewed
CVE-2023-3997
was published
Jul 31, 2023
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to...
High
Unreviewed
CVE-2023-36925
was published
Jul 11, 2023
While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603,...
Moderate
Unreviewed
CVE-2023-36924
was published
Jul 11, 2023
SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an...
Moderate
Unreviewed
CVE-2023-31405
was published
Jul 11, 2023
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an attacker can use a specially...
Low
Unreviewed
CVE-2023-32712
was published
Jun 1, 2023
A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that...
Moderate
Unreviewed
CVE-2023-1711
was published
May 30, 2023
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the...
Moderate
Unreviewed
CVE-2023-0595
was published
Feb 24, 2023
Shopware's log module vulnerable to Improper Output Neutralization
Low
CVE-2023-22733
was published
for
shopware/core
(Composer)
Jan 20, 2023
A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an...
Critical
Unreviewed
CVE-2015-10011
was published
Jan 3, 2023
Yapscan's report receiver server vulnerable to path traversal and log injection
High
GHSA-9h6h-9g78-86f7
was published
for
github.com/fkie-cad/yapscan
(Go)
Dec 29, 2022
ProTip!
Advisories are also available from the
GraphQL API