GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,679
Erlang
34
GitHub Actions
26
Go
2,268
Maven
5,000+
npm
3,923
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
105 advisories
Filter by severity
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly...
Moderate
Unreviewed
CVE-2025-46421
was published
Apr 24, 2025
Vestel AC Charger
version
3.75.0 contains a vulnerability that
could enable an attacker to...
High
Unreviewed
CVE-2025-3606
was published
Apr 25, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream
Low
CVE-2025-31363
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Drupal Full Path Disclosure
Moderate
CVE-2024-45440
was published
for
drupal/core
(Composer)
Aug 29, 2024
ses's global contour bindings leak into Compartment lexical scope
High
CVE-2025-32792
was published
for
ses
(npm)
Apr 18, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-39439
was published
Apr 17, 2025
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications...
High
Unreviewed
CVE-2025-30686
was published
Apr 15, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-39589
was published
Apr 16, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-39556
was published
Apr 16, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
High
Unreviewed
CVE-2025-26730
was published
Apr 16, 2025
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that...
Moderate
Unreviewed
CVE-2022-43852
was published
Apr 14, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP...
Moderate
Unreviewed
CVE-2025-32228
was published
Apr 10, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Low
Unreviewed
CVE-2025-31003
was published
Apr 9, 2025
Information disclosure of authentication information in the specific service vulnerability exists...
High
Unreviewed
CVE-2025-27934
was published
Apr 9, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-32164
was published
Apr 8, 2025
Information disclosure while creating MQ channels.
High
Unreviewed
CVE-2024-45549
was published
Apr 7, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J....
Moderate
Unreviewed
CVE-2025-32251
was published
Apr 4, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-32255
was published
Apr 4, 2025
HCL Traveler is affected by an internal path disclosure in a Windows application when the...
Moderate
Unreviewed
CVE-2025-0278
was published
Apr 4, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee...
Moderate
Unreviewed
CVE-2025-31832
was published
Apr 1, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-30802
was published
Apr 1, 2025
tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain...
High
Unreviewed
CVE-2024-36070
was published
May 19, 2024
In getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's...
Low
Unreviewed
CVE-2024-0053
was published
Mar 11, 2024
An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization...
High
Unreviewed
CVE-2024-8313
was published
Mar 25, 2025
AWS CDK CLI prints AWS credentials retrieved by custom credential plugins
Moderate
CVE-2025-2598
was published
for
aws-cdk
(npm)
Mar 21, 2025
ProTip!
Advisories are also available from the
GraphQL API