GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
86 advisories
Filter by severity
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2...
Moderate
Unreviewed
CVE-2023-38013
was published
Jan 25, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in UkrSolution Barcode Generator...
Moderate
Unreviewed
CVE-2025-24597
was published
Jan 31, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in GREYS Korea for WooCommerce...
Moderate
Unreviewed
CVE-2025-24639
was published
Feb 3, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows...
Moderate
Unreviewed
CVE-2025-24567
was published
Feb 14, 2025
Liferay Portal and Liferay DXP Reveals Data via Forms
Moderate
CVE-2025-2565
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Mar 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in AppExperts AppExperts –...
Moderate
Unreviewed
CVE-2025-30609
was published
Mar 24, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Shipmondo Shipmondo – A...
Moderate
Unreviewed
CVE-2025-27001
was published
Mar 28, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in viralloops Viral Loops WP...
Moderate
Unreviewed
CVE-2025-31842
was published
Apr 1, 2025
AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent...
Moderate
Unreviewed
CVE-2025-27244
was published
Apr 2, 2025
Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive...
Moderate
Unreviewed
CVE-2025-26335
was published
Apr 11, 2025
Bullfrog's DNS over TCP bypasses domain filtering
Moderate
CVE-2025-47775
was published
for
bullfrogsec/bullfrog
(GitHub Actions)
May 15, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social...
Moderate
Unreviewed
CVE-2025-39498
was published
May 26, 2025
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables
Moderate
CVE-2025-48934
was published
for
deno
(Rust)
Jun 4, 2025
Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint
Moderate
CVE-2025-48996
was published
for
@haxtheweb/open-apis
(npm)
Jun 5, 2025
The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all...
Moderate
Unreviewed
CVE-2025-5733
was published
Jun 6, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic...
Moderate
Unreviewed
CVE-2025-49294
was published
Jun 6, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Stripe...
Moderate
Unreviewed
CVE-2025-53309
was published
Jun 27, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize...
Moderate
Unreviewed
CVE-2025-53322
was published
Jun 27, 2025
In ConnectWise PSA versions older than 2025.9, a
vulnerability exists where authenticated users...
Moderate
Unreviewed
CVE-2025-7204
was published
Jul 9, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Brainstorm Force SureDash...
Moderate
Unreviewed
CVE-2025-54685
was published
Aug 14, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress allows...
Moderate
Unreviewed
CVE-2025-55710
was published
Aug 14, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows...
Moderate
Unreviewed
CVE-2025-49408
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetEngine allows...
Moderate
Unreviewed
CVE-2025-53196
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetTabs allows...
Moderate
Unreviewed
CVE-2025-53985
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetTricks allows...
Moderate
Unreviewed
CVE-2025-53992
was published
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API