GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,175 advisories
Filter by severity
Insertion of sensitive information into log file vulnerability in Apache APISIX.
This...
Moderate
Unreviewed
CVE-2026-78242
was published
Oct 1, 2026
Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker...
Moderate
Unreviewed
CVE-2026-92872
was published
Sep 30, 2026
Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL...
Moderate
Unreviewed
CVE-2026-81862
was published
Sep 29, 2026
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to...
High
Unreviewed
CVE-2025-71425
was published
Sep 27, 2026
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before...
High
Unreviewed
CVE-2025-71423
was published
Sep 27, 2026
Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and...
Moderate
Unreviewed
CVE-2026-85417
was published
Sep 25, 2026
The Botslab G980H dash camera firmware includes sensitive configuration information, including...
Moderate
Unreviewed
CVE-2026-82716
was published
Sep 24, 2026
An information exposure vulnerability in the job scheduling component of SANnav allows sensitive...
Moderate
Unreviewed
CVE-2026-14442
was published
Sep 24, 2026
Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before...
High
Unreviewed
CVE-2026-14443
was published
Sep 24, 2026
Improper handling of sensitive data during IPsec policy creation and modification in Brocade...
High
Unreviewed
CVE-2026-82372
was published
Sep 24, 2026
Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files...
High
Unreviewed
CVE-2026-82371
was published
Sep 24, 2026
OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys...
High
Unreviewed
CVE-2026-95815
was published
Sep 22, 2026
OpenBao Agent Writes Secrets to Stdout
Low
CVE-2026-77285
was published
for
github.com/openbao/openbao
(Go)
Sep 22, 2026
Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of...
High
Unreviewed
CVE-2026-49810
was published
Sep 21, 2026
OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL...
Moderate
Unreviewed
CVE-2026-93982
was published
Sep 19, 2026
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application...
Moderate
Unreviewed
CVE-2026-92758
was published
Sep 17, 2026
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low
CVE-2026-81870
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlptrace
(Go)
Sep 17, 2026
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
High
CVE-2026-86049
was published
for
jupyter_server
(pip)
Sep 17, 2026
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing...
High
Unreviewed
CVE-2026-92918
was published
Sep 17, 2026
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication...
Low
Unreviewed
CVE-2026-73442
was published
Sep 16, 2026
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet...
Moderate
Unreviewed
CVE-2026-73457
was published
Sep 16, 2026
Insertion of sensitive information into log file in the slow query logging feature in Devolutions...
Moderate
Unreviewed
CVE-2026-92237
was published
Sep 15, 2026
On affected platforms running Arista EOS, under certain circumstances plaintext private keys may...
Moderate
Unreviewed
CVE-2026-73465
was published
Sep 15, 2026
On affected platforms running Arista EOS, under certain circumstances user passwordss may be...
Moderate
Unreviewed
CVE-2026-73466
was published
Sep 15, 2026
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets...
Moderate
Unreviewed
CVE-2026-73467
was published
Sep 15, 2026
ProTip!
Advisories are also available from the
GraphQL API