GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,201
Erlang
31
GitHub Actions
19
Go
1,986
Maven
5,000+
npm
3,702
NuGet
660
pip
3,328
Pub
11
RubyGems
883
Rust
843
Swift
36
Unreviewed advisories
All unreviewed
5,000+
433 advisories
Filter by severity
Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing...
Moderate
Unreviewed
CVE-2022-44587
was published
Jun 21, 2024
SonarQube logs sensitive information
Moderate
CVE-2024-38460
was published
for
org.sonarsource.sonarqube:sonar-web
(Maven)
Jun 16, 2024
The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A...
Moderate
Unreviewed
CVE-2024-27157
was published
Jun 14, 2024
The session cookies, used for authentication, are stored in clear-text logs. An attacker can...
Moderate
Unreviewed
CVE-2024-27156
was published
Jun 14, 2024
Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected...
Moderate
Unreviewed
CVE-2024-27154
was published
Jun 14, 2024
A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user...
Moderate
Unreviewed
CVE-2024-5908
was published
Jun 12, 2024
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause...
Moderate
Unreviewed
CVE-2024-5557
was published
Jun 12, 2024
Insertion of Sensitive Information into Log File vulnerability in Octolize USPS Shipping for...
Moderate
Unreviewed
CVE-2024-32811
was published
Jun 9, 2024
Insertion of Sensitive Information into Log File vulnerability in Lukman Nakib Debug Log – Manger...
Moderate
Unreviewed
CVE-2024-34798
was published
Jun 3, 2024
goreleaser shows environment by default
Moderate
GHSA-f6mm-5fc7-3g3c
was published
for
github.com/goreleaser/goreleaser
(Go)
May 15, 2024
source-controller leaks Azure Storage SAS token into logs
Moderate
CVE-2024-31216
was published
for
github.com/fluxcd/source-controller
(Go)
May 15, 2024
azure-file-csi-driver leaks service account tokens in the logs
Moderate
CVE-2024-3744
was published
for
sigs.k8s.io/azurefile-csi-driver
(Go)
May 15, 2024
Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365...
Moderate
Unreviewed
CVE-2024-34550
was published
May 14, 2024
matrix-sdk-crypto contains a log exposure of private key of the server-side key backup
Moderate
CVE-2024-34353
was published
for
matrix-sdk-crypto
(Rust)
May 13, 2024
IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log...
Moderate
Unreviewed
CVE-2023-40694
was published
May 7, 2024
A highly privileged account can overwrite arbitrary files on the system with log output. The log...
Moderate
Unreviewed
CVE-2024-28072
was published
May 3, 2024
Insertion of Sensitive Information into Log File vulnerability in Jordy Meow WP Media Cleaner...
Moderate
Unreviewed
CVE-2024-33922
was published
May 2, 2024
Vault Enterprise, when configured with performance standby nodes and a configured audit device,...
Moderate
Unreviewed
CVE-2024-2877
was published
Apr 30, 2024
Jberet: jberet-core logging database credentials
Moderate
CVE-2024-1102
was published
for
org.jberet:jberet-core
(Maven)
Apr 25, 2024
Sensitive Information leak via Log File in Kubernetes
Moderate
CVE-2020-8563
was published
for
github.com/kubernetes/kubernetes
(Go)
Apr 24, 2024
Sensitive Information leak via Log File in Kubernetes
Moderate
CVE-2020-8566
was published
for
github.com/kubernetes/kubernetes
(Go)
Apr 24, 2024
Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to...
Moderate
Unreviewed
CVE-2024-32788
was published
Apr 24, 2024
Insertion of Sensitive Information into Log File vulnerability in Very Good Plugins WP Fusion...
Moderate
Unreviewed
CVE-2024-32796
was published
Apr 24, 2024
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center...
Moderate
Unreviewed
CVE-2023-6833
was published
Apr 23, 2024
IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that...
Moderate
Unreviewed
CVE-2023-22869
was published
Apr 19, 2024
ProTip!
Advisories are also available from the
GraphQL API