GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,351
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
368 advisories
Filter by severity
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made...
Moderate
Unreviewed
CVE-2024-2302
was published
Apr 9, 2024
Using API in the 2N OS device, authorized user can enable logging, which discloses valid...
Moderate
Unreviewed
CVE-2024-13416
was published
Feb 6, 2025
When users log in through the webUI or API using local authentication, BIG-IP Next Central...
Moderate
Unreviewed
CVE-2025-23413
was published
Feb 5, 2025
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade...
Moderate
Unreviewed
CVE-2022-43935
was published
Feb 4, 2025
Possible information exposure through log file vulnerability where sensitive fields are recorded...
Moderate
Unreviewed
CVE-2022-43937
was published
Feb 4, 2025
Brocade SANnav versions before 2.2.2 log Brocade Fabric OS switch passwords when debugging is...
Moderate
Unreviewed
CVE-2022-43936
was published
Feb 4, 2025
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to...
Moderate
Unreviewed
CVE-2024-29955
was published
Apr 18, 2024
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade...
Moderate
Unreviewed
CVE-2022-43933
was published
Feb 4, 2025
Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some...
Moderate
Unreviewed
CVE-2024-48852
was published
Jan 29, 2025
Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)...
Moderate
Unreviewed
CVE-2025-24389
was published
Jan 27, 2025
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2...
Moderate
Unreviewed
CVE-2023-38271
was published
Jan 25, 2025
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
Moderate
Unreviewed
CVE-2025-24457
was published
Jan 21, 2025
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13...
Moderate
Unreviewed
CVE-2024-45091
was published
Jan 21, 2025
Under certain log settings the IAM or CORE service will log credentials in the iam logfile in...
Moderate
Unreviewed
CVE-2024-11923
was published
Jan 18, 2025
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be...
Moderate
Unreviewed
CVE-2024-12226
was published
Jan 16, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21318
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21316
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21320
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21319
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21323
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21321
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21317
was published
Jan 14, 2025
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an...
Moderate
Unreviewed
CVE-2024-40679
was published
Jan 8, 2025
Windows Desired State Configuration (DSC) Information Disclosure Vulnerability.
Moderate
Unreviewed
CVE-2022-30148
was published
Jun 16, 2022
Disclosure of sensitive information in HikVision camera driver's log file in XProtect Device Pack...
Moderate
Unreviewed
CVE-2024-12569
was published
Dec 19, 2024
ProTip!
Advisories are also available from the
GraphQL API