GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,730
Erlang
35
GitHub Actions
29
Go
2,306
Maven
5,000+
npm
3,947
NuGet
711
pip
3,727
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,575 advisories
Filter by severity
An isolated local disclosure of information and potential isolated local arbitrary code execution...
High
Unreviewed
CVE-2022-28638
was published
Sep 21, 2022
Exposure of private personal information to an unauthorized actor in the user vaults component of...
High
Unreviewed
CVE-2025-5334
was published
May 29, 2025
Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password
Moderate
CVE-2021-29043
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55...
Moderate
Unreviewed
CVE-2025-5064
was published
May 27, 2025
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote...
Moderate
Unreviewed
CVE-2025-5281
was published
May 27, 2025
Rancher's SAML-based login via CLI can be denied by unauthenticated users
Moderate
CVE-2025-23387
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Script elements loading cross-origin resources generated load and error events which leaked...
Moderate
Unreviewed
CVE-2025-5266
was published
May 27, 2025
Grafana Alerting VictorOps integration could be exposed to users with Viewer permission
Moderate
CVE-2024-11741
was published
for
github.com/grafana/grafana
(Go)
Jan 31, 2025
An information disclosure issue was addressed by removing the vulnerable code. This issue is...
Moderate
Unreviewed
CVE-2022-32849
was published
Sep 25, 2022
This issue was addressed with improved redaction of sensitive information. This issue is fixed in...
Moderate
Unreviewed
CVE-2023-42884
was published
Dec 12, 2023
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Moderate
CVE-2025-26795
was published
for
org.apache.iotdb:iotdb-jdbc
(Maven)
May 14, 2025
A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1....
Moderate
Unreviewed
CVE-2025-5184
was published
May 26, 2025
An unauthenticated remote attacker can access information about running processes via the SNMP...
High
Unreviewed
CVE-2025-41654
was published
May 26, 2025
Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read...
Moderate
Unreviewed
CVE-2024-54188
was published
May 22, 2025
Moodle sensitive information disclosure
Moderate
CVE-2015-5340
was published
for
moodle/moodle
(Composer)
May 13, 2022
XML External Entity Injection in XStream
High
CVE-2016-3674
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Jun 30, 2020
PrinterShare Android application allows the capture of Gmail authentication tokens that can be...
Critical
Unreviewed
CVE-2025-5098
was published
May 23, 2025
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5...
Moderate
Unreviewed
CVE-2022-32818
was published
Sep 25, 2022
A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the...
Moderate
Unreviewed
CVE-2022-35247
was published
Sep 25, 2022
Medtronic 2090 CareLink Programmer all versions The affected product uses a virtual private...
High
Unreviewed
CVE-2018-10596
was published
May 13, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS...
Moderate
Unreviewed
CVE-2022-32825
was published
Sep 25, 2022
The issue was addressed with improved handling of caches. This issue is fixed in Security Update...
Moderate
Unreviewed
CVE-2022-32805
was published
Sep 25, 2022
An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted...
High
Unreviewed
CVE-2024-53359
was published
May 20, 2025
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle...
Moderate
Unreviewed
CVE-2019-1081
was published
May 24, 2022
An information disclosure vulnerability exists when the Windows GDI component improperly...
Moderate
Unreviewed
CVE-2019-1010
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API