GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,074
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
240 advisories
Filter by severity
Philips Gemini PET/CT family software stores sensitive information in a removable media device...
Low
Unreviewed
CVE-2021-27456
was published
Mar 24, 2022
Spoofing attack in swagger-ui
Moderate
CVE-2018-25031
was published
for
swagger-ui
(npm)
Mar 12, 2022
Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.
Moderate
Unreviewed
CVE-2022-0881
was published
Mar 10, 2022
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be...
High
Unreviewed
CVE-2022-25264
was published
Feb 26, 2022
Insecure Storage of Sensitive Information in Microweber
High
CVE-2022-0724
was published
for
microweber/microweber
(Composer)
Feb 24, 2022
Authentication bypass in Apache Kylin
Moderate
CVE-2020-13937
was published
for
org.apache.kylin:kylin
(Maven)
Feb 10, 2022
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control ...
Moderate
Unreviewed
CVE-2022-21823
was published
Jan 11, 2022
An issue existed in the storage of sensitive tokens. This issue was addressed by placing the...
Moderate
Unreviewed
CVE-2017-13909
was published
Dec 24, 2021
The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a...
High
Unreviewed
CVE-2021-42913
was published
Dec 21, 2021
Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02...
Low
Unreviewed
CVE-2021-25522
was published
Dec 9, 2021
Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows...
Low
Unreviewed
CVE-2021-25523
was published
Dec 9, 2021
Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to...
Low
Unreviewed
CVE-2021-25524
was published
Dec 9, 2021
Improper use of cryptographic key in wal-g
High
CVE-2021-38599
was published
for
github.com/wal-g/wal-g
(Go)
Sep 2, 2021
Sensitive Data Exposure in miniorange_saml
High
CVE-2021-36786
was published
for
miniorange/miniorange-saml
(Composer)
Sep 1, 2021
Remote code execution in Apache Tapestry
Critical
CVE-2021-27850
was published
for
org.apache.tapestry:tapestry-core
(Maven)
Jun 16, 2021
ProTip!
Advisories are also available from the
GraphQL API