GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
56 advisories
Filter by severity
changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
High
CVE-2024-56509
was published
for
changedetection.io
(pip)
Dec 27, 2024
`Cookie` HTTP header isn't stripped on cross-origin redirects
High
CVE-2023-43804
was published
for
urllib3
(pip)
Oct 2, 2023
OpenStack Swift Discloses Secret URLs to Timing Attack
High
CVE-2014-0006
was published
for
swift
(pip)
May 17, 2022
OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary file
High
CVE-2015-5163
was published
for
glance
(pip)
May 17, 2022
OpenStack Nova Live migration can leak root disk into ephemeral storage
High
CVE-2013-7130
was published
for
nova
(pip)
May 17, 2022
Cookie and header exposure in twisted
High
CVE-2022-21712
was published
for
Twisted
(pip)
Feb 7, 2022
MotionEye allows attackers to access sensitive information
High
CVE-2022-25568
was published
for
motioneye
(pip)
Mar 25, 2022
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
High
CVE-2023-47117
was published
for
label-studio
(pip)
Nov 14, 2023
Apache DolphinScheduler sensitive information disclosure
High
CVE-2023-48796
was published
for
apache-dolphinscheduler
(Maven)
Nov 24, 2023
txAWS AWSServiceEndpoint defaults to not verifying server certificates
High
CVE-2017-1000007
was published
for
txaws
(pip)
May 17, 2022
TripleO Heat templates might allow remote attackers to obtain sensitive information from private containers
High
CVE-2015-5271
was published
for
tripleo-heat-templates
(pip)
May 17, 2022
Trac reStructuredText breach of privacy and denial of service vulnerability
High
CVE-2006-3695
was published
for
trac
(pip)
May 1, 2022
Apache Airflow information exposure vulnerability
High
CVE-2023-40712
was published
for
apache-airflow
(pip)
Sep 12, 2023
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
High
CVE-2023-42781
was published
for
apache-airflow
(pip)
Nov 12, 2023
Apache Airflow information disclosure vulnerability
High
CVE-2022-46651
was published
for
apache-airflow
(pip)
Jul 12, 2023
Apache Airflow vulnerable to exposure of sensitive information
High
CVE-2023-35005
was published
for
apache-airflow
(pip)
Jun 19, 2023
Ansible sensitive information disclosure
High
CVE-2018-16876
was published
for
ansible
(pip)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in ansible
High
CVE-2019-10217
was published
for
ansible
(pip)
Oct 12, 2021
Unsafe handling of user-specified cookies in treq
High
CVE-2022-23607
was published
for
treq
(pip)
Feb 1, 2022
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
CVE-2024-32498
was published
for
cinder
(pip)
Jul 5, 2024
Splash authentication credentials potentially leaked to target websites
High
CVE-2021-41124
was published
for
scrapy-splash
(pip)
Oct 6, 2021
Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager
High
CVE-2021-21336
was published
for
Products.PluggableAuthService
(pip)
Mar 8, 2021
Paramiko Unsafe randomness usage may allow access to sensitive information
High
CVE-2008-0299
was published
for
paramiko
(pip)
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API