GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,697
Erlang
34
GitHub Actions
28
Go
2,289
Maven
5,000+
npm
3,936
NuGet
708
pip
3,706
Pub
12
RubyGems
919
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
380 advisories
Filter by severity
Argo-cd authenticated users can enumerate clusters by name
Moderate
CVE-2024-36106
was published
for
github.com/argoproj/argo-cd
(Go)
Jun 6, 2024
silverstripe/framework may disclose database credentials during connection failure
Moderate
GHSA-m2hh-2m46-x6j5
was published
for
silverstripe/framework
(Composer)
May 28, 2024
github.com/huandu/facebook may expose access_token in error message.
Low
CVE-2024-35232
was published
for
github.com/huandu/facebook/v2
(Go)
May 24, 2024
An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application...
Moderate
Unreviewed
CVE-2024-31844
was published
May 21, 2024
Passbolt Api Retrieval of HTTP-only cookies
Low
GHSA-f5pp-pmq8-gp46
was published
for
passbolt/passbolt_api
(Composer)
May 20, 2024
Grafana User enumeration via forget password
High
CVE-2022-39307
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of...
Critical
Unreviewed
CVE-2024-28285
was published
May 14, 2024
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain...
Low
Unreviewed
CVE-2023-23474
was published
May 3, 2024
An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via...
Moderate
Unreviewed
CVE-2024-30614
was published
Apr 12, 2024
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-28939
was published
Apr 9, 2024
In the Linux kernel, the following vulnerability has been resolved:
spi: spi-fsl-dspi: Fix a...
Moderate
Unreviewed
CVE-2021-47161
was published
Mar 25, 2024
.NET Framework Information Disclosure Vulnerability
High
Unreviewed
CVE-2024-29059
was published
Mar 23, 2024
IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive...
Low
Unreviewed
CVE-2022-32756
was published
Mar 22, 2024
A vulnerability was found in Nway Pro 9. It has been rated as problematic. Affected by this issue...
Moderate
Unreviewed
CVE-2024-2009
was published
Feb 29, 2024
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6,...
Moderate
Unreviewed
CVE-2023-5617
was published
Feb 29, 2024
Apache Superset: Improper error handling on alerts
Moderate
CVE-2024-27315
was published
for
apache-superset
(pip)
Feb 28, 2024
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product...
Moderate
Unreviewed
CVE-2024-21866
was published
Feb 2, 2024
An email address enumeration vulnerability exists in the password reset function of SEO Panel...
Moderate
Unreviewed
CVE-2024-22646
was published
Jan 30, 2024
A Missing Authentication for Critical Function vulnerability combined with a Generation of Error...
Moderate
Unreviewed
CVE-2024-21619
was published
Jan 26, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an...
Moderate
Unreviewed
CVE-2023-47152
was published
Jan 22, 2024
Exposure of sensitive information in ClickHouse
High
CVE-2024-23689
was published
for
com.clickhouse:clickhouse-client
(Maven)
Jan 19, 2024
Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2024-21733
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jan 19, 2024
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device...
Moderate
Unreviewed
CVE-2023-49107
was published
Jan 16, 2024
Windows TCP/IP Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-21313
was published
Jan 9, 2024
@backstage/backend-app-api leaks GitLab access tokens
High
CVE-2023-6944
was published
for
@backstage/backend-app-api
(npm)
Jan 4, 2024
ProTip!
Advisories are also available from the
GraphQL API