GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,660
Maven
5,000+
npm
4,289
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
193 advisories
Filter by severity
A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope...
High
Unreviewed
CVE-2024-8550
was published
Feb 10, 2025
School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing...
Critical
Unreviewed
CVE-2025-1144
was published
Feb 11, 2025
An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to...
Moderate
Unreviewed
CVE-2025-1212
was published
Feb 12, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-26758
was published
Feb 17, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo...
Moderate
Unreviewed
CVE-2025-26911
was published
Feb 25, 2025
Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak...
Low
Unreviewed
CVE-2024-11035
was published
Mar 5, 2025
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3...
Low
Unreviewed
CVE-2024-52905
was published
Mar 10, 2025
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of...
Moderate
Unreviewed
CVE-2025-23382
was published
Mar 19, 2025
langchain-core allows unauthorized users to read arbitrary files from the host file system
Moderate
CVE-2024-10940
was published
for
langchain-core
(pip)
Mar 20, 2025
AWS CDK CLI prints AWS credentials retrieved by custom credential plugins
Moderate
CVE-2025-2598
was published
for
aws-cdk
(npm)
Mar 21, 2025
An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization...
High
Unreviewed
CVE-2024-8313
was published
Mar 25, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-30802
was published
Apr 1, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee...
Moderate
Unreviewed
CVE-2025-31832
was published
Apr 1, 2025
HCL Traveler is affected by an internal path disclosure in a Windows application when the...
Moderate
Unreviewed
CVE-2025-0278
was published
Apr 4, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J....
Moderate
Unreviewed
CVE-2025-32251
was published
Apr 4, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-32255
was published
Apr 4, 2025
Information disclosure while creating MQ channels.
High
Unreviewed
CVE-2024-45549
was published
Apr 7, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-32164
was published
Apr 8, 2025
Information disclosure of authentication information in the specific service vulnerability exists...
High
Unreviewed
CVE-2025-27934
was published
Apr 9, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Low
Unreviewed
CVE-2025-31003
was published
Apr 9, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP...
Moderate
Unreviewed
CVE-2025-32228
was published
Apr 10, 2025
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that...
Moderate
Unreviewed
CVE-2022-43852
was published
Apr 14, 2025
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications...
High
Unreviewed
CVE-2025-30686
was published
Apr 15, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
High
Unreviewed
CVE-2025-26730
was published
Apr 16, 2025
ProTip!
Advisories are also available from the
GraphQL API