GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
122 advisories
Filter by severity
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications...
High
Unreviewed
CVE-2025-30686
was published
Apr 15, 2025
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that...
Moderate
Unreviewed
CVE-2022-43852
was published
Apr 14, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP...
Moderate
Unreviewed
CVE-2025-32228
was published
Apr 10, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Low
Unreviewed
CVE-2025-31003
was published
Apr 9, 2025
Information disclosure of authentication information in the specific service vulnerability exists...
High
Unreviewed
CVE-2025-27934
was published
Apr 9, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-32164
was published
Apr 8, 2025
Information disclosure while creating MQ channels.
High
Unreviewed
CVE-2024-45549
was published
Apr 7, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J....
Moderate
Unreviewed
CVE-2025-32251
was published
Apr 4, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-32255
was published
Apr 4, 2025
HCL Traveler is affected by an internal path disclosure in a Windows application when the...
Moderate
Unreviewed
CVE-2025-0278
was published
Apr 4, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee...
Moderate
Unreviewed
CVE-2025-31832
was published
Apr 1, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-30802
was published
Apr 1, 2025
An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization...
High
Unreviewed
CVE-2024-8313
was published
Mar 25, 2025
AWS CDK CLI prints AWS credentials retrieved by custom credential plugins
Moderate
CVE-2025-2598
was published
for
aws-cdk
(npm)
Mar 21, 2025
langchain-core allows unauthorized users to read arbitrary files from the host file system
Moderate
CVE-2024-10940
was published
for
langchain-core
(pip)
Mar 20, 2025
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of...
Moderate
Unreviewed
CVE-2025-23382
was published
Mar 19, 2025
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3...
Low
Unreviewed
CVE-2024-52905
was published
Mar 10, 2025
Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak...
Low
Unreviewed
CVE-2024-11035
was published
Mar 5, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo...
Moderate
Unreviewed
CVE-2025-26911
was published
Feb 25, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
Moderate
Unreviewed
CVE-2025-26758
was published
Feb 17, 2025
An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to...
Moderate
Unreviewed
CVE-2025-1212
was published
Feb 12, 2025
School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing...
Critical
Unreviewed
CVE-2025-1144
was published
Feb 11, 2025
A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope...
High
Unreviewed
CVE-2024-8550
was published
Feb 10, 2025
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever...
Critical
Unreviewed
CVE-2024-36554
was published
Feb 6, 2025
ProTip!
Advisories are also available from the
GraphQL API