GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
315 advisories
Filter by severity
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a...
Moderate
Unreviewed
CVE-2024-39725
was published
Dec 25, 2024
Apache Hive and Spark: CookieSigner exposes the correct signature when message verification fails
High
CVE-2024-23945
was published
for
org.apache.hive:hive-service
(Maven)
Dec 23, 2024
IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow a remote attacker to obtain...
Moderate
Unreviewed
CVE-2024-52897
was published
Dec 19, 2024
IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker...
Moderate
Unreviewed
CVE-2024-52896
was published
Dec 19, 2024
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1
could allow a remote...
Moderate
Unreviewed
CVE-2024-49818
was published
Dec 17, 2024
Generation of Error Message Containing Sensitive Information vulnerability in Dave Kiss...
Moderate
Unreviewed
CVE-2024-54366
was published
Dec 16, 2024
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive...
Moderate
Unreviewed
CVE-2024-51460
was published
Dec 11, 2024
Apache Superset: Error verbosity exposes metadata in analytics databases
Moderate
CVE-2024-53948
was published
for
apache-superset
(pip)
Dec 9, 2024
phpMyFAQ Generates an Error Message Containing Sensitive Information if database server is not available
High
CVE-2024-54141
was published
for
thorsten/phpmyfaq
(Composer)
Dec 6, 2024
Sentry improper error handling leaks Application Integration Client Secret
Moderate
CVE-2024-53253
was published
for
sentry
(pip)
Nov 22, 2024
Moodle leaks user names
Moderate
CVE-2024-48896
was published
for
moodle/moodle
(Composer)
Nov 18, 2024
Generation of Error Message Containing Sensitive Information in janeczku/calibre-web
Moderate
CVE-2021-3986
was published
for
calibreweb
(pip)
Nov 15, 2024
The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not...
Unknown
Unreviewed
CVE-2023-40457
was published
Nov 11, 2024
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive...
Moderate
Unreviewed
CVE-2024-30141
was published
Nov 7, 2024
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs...
High
Unreviewed
CVE-2024-51560
was published
Nov 4, 2024
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api...
High
Unreviewed
CVE-2024-39719
was published
Oct 31, 2024
Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti...
Moderate
Unreviewed
CVE-2024-50512
was published
Oct 30, 2024
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can...
Low
Unreviewed
CVE-2023-50355
was published
Oct 24, 2024
SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non...
Moderate
Unreviewed
CVE-2024-45713
was published
Oct 17, 2024
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows...
Moderate
Unreviewed
CVE-2024-44762
was published
Oct 16, 2024
open-webui allows enumeration of file names and traversal of directories by observing the error messages
Low
CVE-2024-7038
was published
for
open-webui
(pip)
Oct 9, 2024
Jenkins exposes multi-line secrets through error messages
Moderate
CVE-2024-47803
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Oct 2, 2024
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for...
Moderate
Unreviewed
CVE-2024-7426
was published
Sep 25, 2024
The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions...
Moderate
Unreviewed
CVE-2024-6544
was published
Sep 13, 2024
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15...
Moderate
Unreviewed
CVE-2024-5435
was published
Sep 12, 2024
ProTip!
Advisories are also available from the
GraphQL API