GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
55 advisories
Filter by severity
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory,...
Low
Unreviewed
CVE-2026-56571
was published
Jul 31, 2026
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages...
Low
Unreviewed
CVE-2026-56568
was published
Jul 31, 2026
HCL Connections is vulnerable to information disclosure which could allow a user to obtain...
Low
Unreviewed
CVE-2026-56537
was published
Jul 27, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
Low
CVE-2026-45723
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability....
Low
Unreviewed
CVE-2025-52611
was published
Jun 4, 2026
Vaadin Build Plugins is Affected by a Possible Information Disclosure Vulnerability
Low
CVE-2026-7860
was published
for
com.vaadin:flow-gradle-plugin
(Maven)
May 19, 2026
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application...
Low
Unreviewed
CVE-2025-59853
was published
May 6, 2026
Spring gRPC AuthenticationException messages are reflected to remote client
Low
CVE-2026-40969
was published
for
org.springframework.grpc:spring-grpc
(Maven)
Apr 28, 2026
HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of...
Low
Unreviewed
CVE-2025-52641
was published
Apr 15, 2026
Keycloak's identity-first login flow exposes user information
Low
CVE-2026-4633
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 23, 2026
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose...
Low
Unreviewed
CVE-2025-55250
was published
Jan 19, 2026
HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes...
Low
Unreviewed
CVE-2025-31998
was published
Oct 12, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
Low
Unreviewed
CVE-2024-41984
was published
Aug 12, 2025
When a Web User without Create permission on subfolders attempts to upload a file to a non...
Low
Unreviewed
CVE-2025-0049
was published
Apr 28, 2025
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive...
Low
Unreviewed
CVE-2024-55895
was published
Mar 29, 2025
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles...
Low
Unreviewed
CVE-2025-31141
was published
Mar 27, 2025
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed...
Low
Unreviewed
CVE-2024-56495
was published
Feb 27, 2025
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed...
Low
Unreviewed
CVE-2024-56811
was published
Feb 27, 2025
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed...
Low
Unreviewed
CVE-2024-56496
was published
Feb 27, 2025
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed...
Low
Unreviewed
CVE-2024-56810
was published
Feb 27, 2025
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed...
Low
Unreviewed
CVE-2024-56494
was published
Feb 27, 2025
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed...
Low
Unreviewed
CVE-2024-56493
was published
Feb 27, 2025
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed...
Low
Unreviewed
CVE-2024-56812
was published
Feb 27, 2025
The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error...
Low
Unreviewed
CVE-2024-52611
was published
Feb 11, 2025
ProTip!
Advisories are also available from the
GraphQL API