GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            6,748 advisories
        Filter by severity
        
      
      
    
                    
                      rack-mini-profiler allows remote attackers to obtain sensitive information about allocated strings and objects
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-4442
                      
                      was published
                        for
                        
                          rack-mini-profiler
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-1840
                      
                      was published
                        for
                        
                          jquery-rails
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Exposure of Sensitive Information in bio-basespace-sdk
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-7111
                      
                      was published
                        for
                        
                          bio-basespace-sdk
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      newrelic_rpm Gem Discloses Sensitive Information
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-0284
                      
                      was published
                        for
                        
                          newrelic_rpm
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack and activesupport vulnerable to information leaks
                    
                      
  Moderate
                    
                
                      
                        CVE-2009-3086
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Moderate severity vulnerability that affects rails
                    
                      
  Moderate
                    
                
                      
                        CVE-2007-5379
                      
                      was published
                        for
                        
                          rails
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      http vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-1828
                      
                      was published
                        for
                        
                          http
                        
                        (RubyGems)
                      Mar 13, 2018 
                    
                  
                    
                      Information Exposure on Case Insensitive File Systems in serve
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-3809
                      
                      was published
                        for
                        
                          serve
                        
                        (npm)
                      Jul 18, 2018 
                    
                  
                    
                      Invalid Curve Attack in node-jose
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-16007
                      
                      was published
                        for
                        
                          node-jose
                        
                        (npm)
                      Jul 20, 2018 
                    
                  
                    
                      Gollum Exposure of Sensitive Information
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-7314
                      
                      was published
                        for
                        
                          gollum
                        
                        (RubyGems)
                      Aug 28, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.apache.qpid:proton-j
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-2166
                      
                      was published
                        for
                        
                          org.apache.qpid:proton-j
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Tika Server exposes sensitive information
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-3271
                      
                      was published
                        for
                        
                          org.apache.tika:tika-server
                        
                        (Maven)
                      Oct 17, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-7940
                      
                      was published
                        for
                        
                          org.bouncycastle:bcprov-jdk14
                        
                        (Maven)
                      Oct 17, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.apache.storm:storm-core
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-1332
                      
                      was published
                        for
                        
                          org.apache.storm:storm-core
                        
                        (Maven)
                      Oct 17, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.apache.mesos:mesos
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-8023
                      
                      was published
                        for
                        
                          org.apache.mesos:mesos
                        
                        (Maven)
                      Oct 17, 2018 
                    
                  
                    
                      keycloak-core vulnerable to timing attacks against JWS token verification
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-2585
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-core
                        
                        (Maven)
                      Oct 18, 2018 
                    
                  
                    
                      keycloak-core discloses system properties
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-2582
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-core
                        
                        (Maven)
                      Oct 18, 2018 
                    
                  
                    
                      Exposure of Sensitive Information to an Unauthorized Actor in Apache syncope-cope
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-1322
                      
                      was published
                        for
                        
                          org.apache.syncope:syncope-core
                        
                        (Maven)
                      Nov 6, 2018 
                    
                  
                    
                      Exposure of Sensitive Information to an Unauthorized Actor in activestorage
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-16477
                      
                      was published
                        for
                        
                          activestorage
                        
                        (RubyGems)
                      Dec 5, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-15713
                      
                      was published
                        for
                        
                          org.apache.hadoop:hadoop-main
                        
                        (Maven)
                      Dec 21, 2018 
                    
                  
                    
                      Insecure Default Configuration in airbrake
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-10530
                      
                      was published
                        for
                        
                          airbrake
                        
                        (npm)
                      Feb 18, 2019 
                    
                  
                    
                      Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-12625
                      
                      was published
                        for
                        
                          org.apache.hive:hive
                        
                        (Maven)
                      Mar 14, 2019 
                    
                  
                    
                      Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark via crafted URL
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-8024
                      
                      was published
                        for
                        
                          org.apache.spark:spark-core_2.10
                        
                        (Maven)
                      Mar 14, 2019 
                    
                  
                    
                      Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-1334
                      
                      was published
                        for
                        
                          org.apache.spark:spark-core_2.10
                        
                        (Maven)
                      Mar 14, 2019 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API