GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,669
Erlang
34
GitHub Actions
26
Go
2,261
Maven
5,000+
npm
3,910
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,026 advisories
Filter by severity
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2025-32700
was published
Apr 10, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2025-32698
was published
Apr 10, 2025
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user...
Low
Unreviewed
CVE-2024-42208
was published
Apr 4, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
This issue was addressed by restricting options offered on a locked device. This issue is fixed...
Low
Unreviewed
CVE-2024-44179
was published
Mar 10, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
CVE-2025-27221
was published
for
uri
(RubyGems)
Mar 3, 2025
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user...
Low
Unreviewed
CVE-2024-23563
was published
Feb 12, 2025
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0...
Low
Unreviewed
CVE-2024-52966
was published
Feb 11, 2025
In affected versions of Octopus Server the preview import feature could be leveraged to identify...
Low
Unreviewed
CVE-2025-0525
was published
Feb 11, 2025
A privacy issue was addressed with improved private data redaction for log entries. This issue is...
Low
Unreviewed
CVE-2024-54475
was published
Jan 28, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2025-23073
was published
Jan 14, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2025-23074
was published
Jan 14, 2025
HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response...
Low
Unreviewed
CVE-2024-42179
was published
Jan 13, 2025
There is an information disclosure vulnerability in several smartphones. The system has a logic...
Low
Unreviewed
CVE-2020-9082
was published
Dec 27, 2024
There is an information vulnerability in Huawei smartphones. A function in a module can be called...
Low
Unreviewed
CVE-2020-9089
was published
Dec 27, 2024
This issue affects:
Secomea GateManager
Version 9.5 and all prior versions.
Protection Mechanism...
Low
Unreviewed
CVE-2021-32007
was published
Dec 13, 2024
In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions...
Low
Unreviewed
CVE-2024-53245
was published
Dec 10, 2024
Firepad allows insecure document access
Low
CVE-2024-51210
was published
for
firepad
(npm)
Dec 4, 2024
ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This...
Low
Unreviewed
CVE-2024-7391
was published
Nov 23, 2024
Moodle has user information visibility control issues in gradebook reports
Low
CVE-2024-43429
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information...
Low
Unreviewed
CVE-2024-48011
was published
Nov 8, 2024
Symfony allows internal address and port enumeration by NoPrivateNetworkHttpClient
Low
CVE-2024-50342
was published
for
symfony/http-client
(Composer)
Nov 6, 2024
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere...
Low
Unreviewed
CVE-2024-30106
was published
Oct 29, 2024
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). ...
Low
Unreviewed
CVE-2024-21209
was published
Oct 15, 2024
ProTip!
Advisories are also available from the
GraphQL API