GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,941
Erlang
29
GitHub Actions
16
Go
1,722
Maven
4,952
npm
3,481
NuGet
605
pip
3,049
Pub
10
RubyGems
832
Rust
778
Swift
34
Unreviewed advisories
All unreviewed
5,000+
1,468 advisories
Filter by severity
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8,...
High
Unreviewed
CVE-2023-3413
was published
Sep 29, 2023
OpenStack Heat information leak vulnerability
High
CVE-2023-1625
was published
for
openstack-heat
(pip)
Sep 24, 2023
** UNSUPPPORTED WHEN ASSIGNED ** Exposure of sensitive information in ekorCCP and ekorRCI,...
High
Unreviewed
CVE-2022-47554
was published
Sep 19, 2023
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure...
High
Unreviewed
CVE-2023-4876
was published
Sep 10, 2023
Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in...
High
Unreviewed
CVE-2023-41741
was published
Aug 31, 2023
IBM InfoSphere Information Systems 11.7 could expose information about the host system and...
High
Unreviewed
CVE-2023-24959
was published
Aug 28, 2023
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based...
High
Unreviewed
CVE-2023-3705
was published
Aug 24, 2023
Apache Airflow denial of service vulnerability
High
CVE-2023-37379
was published
for
apache-airflow
(pip)
Aug 23, 2023
Because of an authentication flaw an attacker would be capable of generating a web report that...
High
Unreviewed
CVE-2023-25913
was published
Aug 21, 2023
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BUTTERFLY BUTTON...
High
Unreviewed
CVE-2023-40735
was published
Aug 21, 2023
Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an...
High
Unreviewed
CVE-2023-32495
was published
Aug 16, 2023
Yaklang Plugin's Fuzztag Component Allows Unauthorized Local File Reading
High
CVE-2023-40023
was published
for
github.com/yaklang/yaklang
(Go)
Aug 15, 2023
Vulnerability of input parameters being not strictly verified in the AMS module. Successful...
High
Unreviewed
CVE-2023-39383
was published
Aug 13, 2023
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation...
High
Unreviewed
CVE-2023-39393
was published
Aug 13, 2023
.NET Information Disclosure Vulnerability
High
CVE-2023-35391
was published
for
Microsoft.AspNetCore.SignalR.Redis
(NuGet)
Aug 11, 2023
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated...
High
Unreviewed
CVE-2023-39214
was published
Aug 9, 2023
Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD...
High
Unreviewed
CVE-2023-37486
was published
Aug 8, 2023
Apache Airflow Execution with Unnecessary Privileges
High
CVE-2023-39508
was published
for
apache-airflow
(pip)
Aug 5, 2023
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure...
High
Unreviewed
CVE-2023-4139
was published
Aug 4, 2023
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8...
High
Unreviewed
CVE-2023-3993
was published
Aug 2, 2023
Leaking sensitive user information still possible by filtering on private with prefix fields
High
CVE-2023-34235
was published
for
@strapi/database
(npm)
Jul 25, 2023
Pimcore vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
High
CVE-2023-3819
was published
for
pimcore/pimcore
(Composer)
Jul 21, 2023
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs...
High
Unreviewed
CVE-2023-26026
was published
Jul 19, 2023
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An...
High
Unreviewed
CVE-2023-27877
was published
Jul 19, 2023
Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all...
High
Unreviewed
CVE-2023-2268
was published
Jul 15, 2023
ProTip!
Advisories are also available from the
GraphQL API