GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
229 advisories
Filter by severity
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary...
Critical
Unreviewed
CVE-2023-6248
was published
Nov 22, 2023
SQLpage vulnerable to public exposure of database credentials
Critical
CVE-2023-42454
was published
for
sqlpage
(Rust)
Sep 21, 2023
Argo CD cluster secret might leak in cluster details page
Critical
CVE-2023-40029
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 11, 2023
Json response for search reveals Solr credentials
Critical
GHSA-7crc-r3wg-cfgf
was published
for
ezsystems/ezplatform-solr-search-engine
(Composer)
Nov 3, 2023
Json response for search reveals Solr credentials
Critical
GHSA-v6xp-ccvx-w52m
was published
for
ibexa/solr
(Composer)
Nov 3, 2023
Exposure of Sensitive Information to an Unauthorized Actor in AEgir
Critical
CVE-2020-11059
was published
for
aegir
(npm)
May 27, 2020
Anchor CMS Logs Credentials
Critical
CVE-2018-7251
was published
for
anchorcms/anchor-cms
(Composer)
May 13, 2022
tss-lib leaks secret keys in response to incorrectly constructed Paillier moduli
Critical
GHSA-h24c-6p6p-m3vx
was published
for
github.com/bnb-chain/tss-lib
(Go)
Sep 1, 2023
Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code
Critical
CVE-2022-39222
was published
for
github.com/dexidp/dex
(Go)
Oct 3, 2022
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker...
Critical
Unreviewed
CVE-2023-24838
was published
Jul 6, 2023
Airbrake keys not being filtered
Critical
CVE-2019-16060
was published
for
airbrake-ruby
(RubyGems)
Sep 11, 2019
Improper access control allows admin privilege escalation in Argo CD
Critical
CVE-2022-24768
was published
for
github.com/argoproj/argo-cd
(Go)
Mar 24, 2022
angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend
Critical
CVE-2023-28444
was published
for
angular-server-side-configuration
(npm)
Mar 24, 2023
Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to...
Critical
Unreviewed
CVE-2023-0321
was published
Jan 26, 2023
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not...
Critical
Unreviewed
CVE-2021-3688
was published
Aug 27, 2022
libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error...
Critical
Unreviewed
CVE-2010-3845
was published
May 17, 2022
Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to...
Critical
Unreviewed
CVE-2015-5959
was published
May 17, 2022
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices allow remote attackers to obtain sensitive...
Critical
Unreviewed
CVE-2017-14269
was published
May 17, 2022
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP...
Critical
Unreviewed
CVE-2014-8174
was published
May 17, 2022
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc...
Critical
Unreviewed
CVE-2015-5284
was published
May 17, 2022
Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via...
Critical
Unreviewed
CVE-2015-8707
was published
May 17, 2022
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially...
Critical
Unreviewed
CVE-2017-9393
was published
May 17, 2022
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains...
Critical
Unreviewed
CVE-2017-13701
was published
May 17, 2022
An information disclosure vulnerability in the Android media framework (n/a). Product: Android....
Critical
Unreviewed
CVE-2017-13150
was published
May 17, 2022
An information disclosure vulnerability in the Android media framework (n/a). Product: Android....
Critical
Unreviewed
CVE-2017-13149
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API