GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,820
Erlang
36
GitHub Actions
32
Go
2,412
Maven
5,000+
npm
4,050
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,004
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
74 advisories
Filter by severity
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository gnuboard...
High
Unreviewed
CVE-2022-1252
was published
Apr 12, 2022
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information...
Moderate
Unreviewed
CVE-2021-22876
was published
May 24, 2022
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier)...
Moderate
Unreviewed
CVE-2021-28559
was published
May 24, 2022
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription...
Moderate
Unreviewed
CVE-2022-0852
was published
Aug 29, 2022
In affected versions of Octopus Server it was identified that when a sensitive value is a...
Moderate
Unreviewed
CVE-2022-2720
was published
Oct 12, 2022
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA),...
Moderate
Unreviewed
CVE-2022-20942
was published
Nov 4, 2022
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series...
Moderate
Unreviewed
CVE-2023-22918
was published
Apr 24, 2023
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media...
High
Unreviewed
CVE-2023-2703
was published
May 23, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15...
Moderate
Unreviewed
CVE-2023-1936
was published
Jul 11, 2023
Sensitive information disclosure due to spell-jacking. The following products are affected:...
Moderate
Unreviewed
CVE-2023-44156
was published
Sep 27, 2023
Sensitive information disclosure due to excessive collection of system information. The following...
Low
Unreviewed
CVE-2023-44213
was published
Oct 6, 2023
When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the...
Moderate
Unreviewed
CVE-2023-34085
was published
Oct 25, 2023
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Botanik Software...
High
Unreviewed
CVE-2023-5983
was published
Nov 22, 2023
The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser...
Moderate
Unreviewed
CVE-2023-25632
was published
Nov 27, 2023
A privacy issue was addressed with improved private data redaction for log entries. This issue is...
Low
Unreviewed
CVE-2023-42830
was published
Jan 11, 2024
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in...
Low
Unreviewed
CVE-2024-23211
was published
Jan 23, 2024
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
High
Unreviewed
CVE-2024-26192
was published
Feb 24, 2024
Sensitive information disclosure due to excessive collection of system information. The following...
Low
Unreviewed
CVE-2023-48680
was published
Feb 27, 2024
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-29986
was published
Apr 18, 2024
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-29987
was published
Apr 18, 2024
An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive...
High
Unreviewed
CVE-2024-33271
was published
Apr 29, 2024
An issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive...
High
Unreviewed
CVE-2023-50053
was published
Apr 30, 2024
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not...
Moderate
Unreviewed
CVE-2024-4767
was published
May 14, 2024
This issue was addressed with improvements to the noise injection algorithm. This issue is fixed...
Moderate
Unreviewed
CVE-2024-27850
was published
Jun 10, 2024
In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a...
High
Unreviewed
CVE-2024-36677
was published
Jun 19, 2024
ProTip!
Advisories are also available from the
GraphQL API