GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,984
Maven
5,000+
npm
3,701
NuGet
657
pip
3,325
Pub
11
RubyGems
882
Rust
835
Swift
35
Unreviewed advisories
All unreviewed
5,000+
54 advisories
Filter by severity
Improper removal of sensitive information in data source export feature in Devolutions Remote...
Moderate
Unreviewed
CVE-2024-6055
was published
Jun 17, 2024
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: lantiq_etop:...
High
Unreviewed
CVE-2024-49997
was published
Oct 21, 2024
Profile files from TRO600 series radios are extracted in plain-text
and encrypted file formats....
Low
Unreviewed
CVE-2024-41156
was published
Oct 29, 2024
Information management vulnerability in the Gallery module.Successful exploitation of this...
High
Unreviewed
CVE-2023-52376
was published
Feb 18, 2024
Forwarding of confidentials headers to third parties in fluture-node
Low
CVE-2022-24719
was published
for
fluture-node
(npm)
Mar 1, 2022
Windows Kernel-Mode Driver Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-43554
was published
Oct 8, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in irrd
High
CVE-2022-24798
was published
for
irrd
(pip)
Apr 1, 2022
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which...
Moderate
Unreviewed
CVE-2024-7698
was published
Sep 10, 2024
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would...
Unknown
Unreviewed
CVE-2024-29120
was published
Jul 17, 2024
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212]...
Moderate
Unreviewed
CVE-2024-31493
was published
Jun 3, 2024
Information disclosure in podman
Moderate
CVE-2020-14370
was published
for
github.com/containers/podman/v2
(Go)
Apr 24, 2024
Sensitive query parameters logged by default in OpenTelemetry.Instrumentation http and AspNetCore
Moderate
CVE-2024-32028
was published
for
OpenTelemetry.Instrumentation.AspNetCore
(NuGet)
Apr 12, 2024
A known cache speculation vulnerability, known as Branch History Injection (BHI) or Spectre-BHB,...
Moderate
Unreviewed
CVE-2023-3006
was published
May 31, 2023
An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730...
Moderate
Unreviewed
CVE-2019-19362
was published
May 24, 2022
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy...
High
Unreviewed
CVE-2019-11243
was published
May 24, 2022
A design flaw in image processing software that modifies JPEG images might not modify the...
Low
Unreviewed
CVE-2005-0406
was published
May 1, 2022
The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier...
Moderate
Unreviewed
CVE-2002-0704
was published
Apr 30, 2022
AMD microprocessor families 15h to 18h are affected by a new Spectre variant that is able to...
Moderate
Unreviewed
CVE-2022-29900
was published
Jul 13, 2022
Exposure of information in Action Pack
High
CVE-2022-23633
was published
for
actionpack
(RubyGems)
Feb 11, 2022
Sensitive information uncleared after debug/power state transition in the Controller 6000 could...
Low
Unreviewed
CVE-2023-41967
was published
Dec 19, 2023
Jenkins Support Core Plugin stores sensitive data in plain text
Moderate
CVE-2022-25187
was published
for
org.jenkins-ci.plugins:support-core
(Maven)
Feb 16, 2022
Exposure of Sensitive Information in eventsource
Critical
CVE-2022-1650
was published
for
eventsource
(npm)
May 13, 2022
Buildah processes using chroot isolation may leak environment values to intermediate processes
Moderate
CVE-2021-3602
was published
for
github.com/containers/buildah
(Go)
Jul 19, 2021
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a...
Moderate
Unreviewed
CVE-2022-0171
was published
Aug 27, 2022
ProTip!
Advisories are also available from the
GraphQL API