GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,762
NuGet
678
pip
3,447
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
55 advisories
Filter by severity
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access...
High
Unreviewed
CVE-2025-24858
was published
Jan 26, 2025
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2...
Moderate
Unreviewed
CVE-2023-38013
was published
Jan 25, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Code for Recovery 12 Step...
Moderate
Unreviewed
CVE-2025-24582
was published
Jan 24, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WM Options Import...
High
Unreviewed
CVE-2025-23781
was published
Jan 22, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WPDB to Sql allows...
High
Unreviewed
CVE-2025-23774
was published
Jan 22, 2025
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP...
Moderate
Unreviewed
CVE-2024-45653
was published
Jan 19, 2025
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology...
High
Unreviewed
CVE-2021-26566
was published
May 24, 2022
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7...
Low
Unreviewed
CVE-2024-46665
was published
Jan 14, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows...
High
Unreviewed
CVE-2024-13254
was published
Jan 9, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows...
High
Unreviewed
CVE-2024-13259
was published
Jan 9, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable...
High
Unreviewed
CVE-2024-13276
was published
Jan 9, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows...
Unknown
Unreviewed
CVE-2024-13269
was published
Jan 9, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows...
Moderate
Unreviewed
CVE-2025-22303
was published
Jan 7, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in WPSpins Post/Page Copying Tool...
High
Unreviewed
CVE-2024-56300
was published
Jan 7, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation...
Moderate
Unreviewed
CVE-2024-8429
was published
Dec 17, 2024
Insertion of Sensitive Information Into Sent Data vulnerability in wpdebuglog PostBox allows...
Moderate
Unreviewed
CVE-2024-54309
was published
Dec 13, 2024
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows...
High
Unreviewed
CVE-2024-53804
was published
Dec 6, 2024
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba...
Moderate
Unreviewed
CVE-2023-34968
was published
Jul 20, 2023
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco...
Moderate
Unreviewed
CVE-2021-1425
was published
Nov 18, 2024
Insertion of Sensitive Information Into Sent Data vulnerability in VideoWhisper.Com Contact Forms...
High
Unreviewed
CVE-2024-49235
was published
Oct 17, 2024
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 ...
Moderate
Unreviewed
CVE-2024-6747
was published
Oct 10, 2024
The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
High
Unreviewed
CVE-2023-49261
was published
Jan 12, 2024
The goTenna Pro broadcast key name is always sent unencrypted and could reveal the location of...
Moderate
Unreviewed
CVE-2024-47128
was published
Sep 26, 2024
An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6...
Moderate
Unreviewed
CVE-2023-3399
was published
Nov 6, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16...
Low
Unreviewed
CVE-2023-5831
was published
Nov 6, 2023
ProTip!
Advisories are also available from the
GraphQL API