GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
78 advisories
Filter by severity
Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCore
Moderate
CVE-2024-32028
was published
for
OpenTelemetry.Instrumentation.AspNetCore
(NuGet)
Apr 12, 2024
Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico
Moderate
CVE-2020-13597
was published
for
github.com/projectcalico/calico
(Go)
Feb 15, 2022
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows...
Critical
Unreviewed
CVE-2024-7205
was published
Jul 31, 2024
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative...
Moderate
Unreviewed
CVE-2024-31200
was published
Jul 31, 2024
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php...
Moderate
Unreviewed
CVE-2024-37881
was published
Jun 19, 2024
Undici vulnerable to data leak when using response.arrayBuffer()
Low
CVE-2024-38372
was published
for
undici
(npm)
Jul 9, 2024
Pomerium exposed OAuth2 access and ID tokens in user info endpoint response
Moderate
CVE-2024-39315
was published
for
github.com/pomerium/pomerium
(Go)
Jul 5, 2024
Potential sensitive information disclosed in error reports
Low
CVE-2021-21416
was published
for
django-registration
(pip)
Apr 6, 2021
An attacker with access to the network where the CIRCUTOR Q-SMT is located in its firmware...
High
Unreviewed
CVE-2024-8890
was published
Sep 18, 2024
Audit records for OpenAPI requests may include sensitive information.
This could lead to...
High
Unreviewed
CVE-2023-6916
was published
Apr 10, 2024
The goTenna Pro ATAK Plugin broadcast key name is always sent unencrypted and could reveal the...
Moderate
Unreviewed
CVE-2024-41931
was published
Sep 26, 2024
goTenna Pro ATAK Plugin by default enables frequent unencrypted
Position, Location and...
Moderate
Unreviewed
CVE-2024-43814
was published
Sep 26, 2024
Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel
Low
CVE-2023-3299
was published
for
github.com/hashicorp/nomad
(Go)
Jul 20, 2023
Liferay Portal vulnerable to user impersonation
High
CVE-2024-25148
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 8, 2024
An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10...
Moderate
Unreviewed
CVE-2023-1825
was published
Jun 7, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16...
Moderate
Unreviewed
CVE-2023-4378
was published
Sep 1, 2023
An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8...
Moderate
Unreviewed
CVE-2023-4002
was published
Aug 4, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to...
Low
Unreviewed
CVE-2023-2620
was published
Jul 13, 2023
An issue has been discovered in GitLab DAST scanner affecting all versions starting from 3.0.29...
Moderate
Unreviewed
CVE-2023-1401
was published
Jul 26, 2023
A sensitive information leak issue has been discovered in GitLab EE affecting all versions...
Moderate
Unreviewed
CVE-2023-3102
was published
Jul 21, 2023
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8,...
High
Unreviewed
CVE-2023-3413
was published
Sep 29, 2023
An issue has been discovered in GitLab affecting all versions starting from 11.3 before 16.4.3,...
Moderate
Unreviewed
CVE-2023-3949
was published
Dec 1, 2023
An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6...
Moderate
Unreviewed
CVE-2023-3399
was published
Nov 6, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16...
Low
Unreviewed
CVE-2023-5831
was published
Nov 6, 2023
The goTenna Pro broadcast key name is always sent unencrypted and could reveal the location of...
Moderate
Unreviewed
CVE-2024-47128
was published
Sep 26, 2024
ProTip!
Advisories are also available from the
GraphQL API