GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
37 advisories
Filter by severity
A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
Moderate
Unreviewed
CVE-2022-27671
was published
Apr 13, 2022
A vulnerability in the authentication for the general purpose APIs implementation of Cisco...
Moderate
Unreviewed
CVE-2021-1129
was published
May 24, 2022
A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local...
Moderate
Unreviewed
CVE-2021-1128
was published
May 24, 2022
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling...
Moderate
Unreviewed
CVE-2020-27748
was published
May 24, 2022
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the...
Moderate
Unreviewed
CVE-2019-14849
was published
May 24, 2022
A vulnerability was found in the Linux kernel, where accessing a deallocated instance in...
Moderate
Unreviewed
CVE-2020-27784
was published
Sep 2, 2022
Support bundle generated files could contain sensitive information that might be unwanted to be...
Moderate
Unreviewed
CVE-2020-1770
was published
May 24, 2022
When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and...
Moderate
Unreviewed
CVE-2020-1774
was published
May 24, 2022
An information disclosure vulnerability exists in the challenge functionality of instipod...
Moderate
Unreviewed
CVE-2023-49594
was published
Dec 23, 2023
Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2,...
Moderate
Unreviewed
CVE-2024-25150
was published
Feb 20, 2024
The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3...
Moderate
Unreviewed
CVE-2024-26270
was published
Feb 20, 2024
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password"...
Moderate
Unreviewed
CVE-2024-28173
was published
Mar 6, 2024
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when...
Moderate
Unreviewed
CVE-2019-15580
was published
May 24, 2022
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided...
Moderate
Unreviewed
CVE-2022-27779
was published
Jun 3, 2022
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4...
Moderate
Unreviewed
CVE-2023-32275
was published
Oct 12, 2023
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows...
Critical
Unreviewed
CVE-2024-7205
was published
Jul 31, 2024
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative...
Moderate
Unreviewed
CVE-2024-31200
was published
Jul 31, 2024
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php...
Moderate
Unreviewed
CVE-2024-37881
was published
Jun 19, 2024
An attacker with access to the network where the CIRCUTOR Q-SMT is located in its firmware...
High
Unreviewed
CVE-2024-8890
was published
Sep 18, 2024
Audit records for OpenAPI requests may include sensitive information.
This could lead to...
High
Unreviewed
CVE-2023-6916
was published
Apr 10, 2024
goTenna Pro ATAK Plugin by default enables frequent unencrypted
Position, Location and...
Moderate
Unreviewed
CVE-2024-43814
was published
Sep 26, 2024
The goTenna Pro ATAK Plugin broadcast key name is always sent unencrypted and could reveal the...
Moderate
Unreviewed
CVE-2024-41931
was published
Sep 26, 2024
An issue has been discovered in GitLab EE affecting all versions starting from 15.7 before 15.10...
Moderate
Unreviewed
CVE-2023-1825
was published
Jun 7, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16...
Moderate
Unreviewed
CVE-2023-4378
was published
Sep 1, 2023
An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8...
Moderate
Unreviewed
CVE-2023-4002
was published
Aug 4, 2023
ProTip!
Advisories are also available from the
GraphQL API