GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access...
Critical
Unreviewed
CVE-2018-11717
was published
May 14, 2022
Ionic Team Cordova plugin iOS Keychain version before commit...
Critical
Unreviewed
CVE-2018-1000123
was published
May 14, 2022
Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in...
Critical
Unreviewed
CVE-2017-1000171
was published
May 17, 2022
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5...
Critical
Unreviewed
CVE-2017-6165
was published
May 17, 2022
Argo CD cluster secret might leak in cluster details page
Critical
CVE-2023-40029
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 11, 2023
If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the...
Critical
Unreviewed
CVE-2023-46668
was published
Oct 26, 2023
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion...
Critical
Unreviewed
CVE-2023-36649
was published
Dec 12, 2023
Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage...
Critical
Unreviewed
CVE-2022-36407
was published
Mar 25, 2024
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade,...
Critical
Unreviewed
CVE-2019-15294
was published
May 24, 2022
In the Orbitz application 19.31.1 for Android, the username and password are stored in the log...
Critical
Unreviewed
CVE-2019-17355
was published
May 24, 2022
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are...
Critical
Unreviewed
CVE-2019-17394
was published
May 24, 2022
In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the...
Critical
Unreviewed
CVE-2019-17398
was published
May 24, 2022
In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in...
Critical
Unreviewed
CVE-2019-17396
was published
May 24, 2022
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log...
Critical
Unreviewed
CVE-2019-17395
was published
May 24, 2022
@valtimo/components exposes access token to form.io
Critical
CVE-2024-34706
was published
for
@valtimo/components
(npm)
May 13, 2024
OpenStack Nova logs sensitive context from notification exceptions
Critical
CVE-2017-7214
was published
for
nova
(pip)
May 14, 2022
Ansible Insertion of Sensitive Information into Log File vulnerability
Critical
CVE-2017-7550
was published
for
ansible
(pip)
May 13, 2022
GitHub personal access token leaking into temporary EasyBuild (debug) logs
Critical
CVE-2020-5262
was published
for
easybuild-framework
(pip)
Mar 19, 2020
django-anymail Includes Sensitive Information in Log Files
Critical
CVE-2018-1000089
was published
for
django-anymail
(pip)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API