GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
213 advisories
Filter by severity
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3...
Moderate
Unreviewed
CVE-2018-10624
was published
May 13, 2022
katello SQL Injection vulnerability
Moderate
CVE-2018-14623
was published
for
katello
(RubyGems)
May 13, 2022
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using...
Moderate
Unreviewed
CVE-2019-7550
was published
May 13, 2022
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of...
Moderate
Unreviewed
CVE-2018-14907
was published
May 13, 2022
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP...
Moderate
Unreviewed
CVE-2010-3332
was published
May 13, 2022
When handling a mismatched pre-authentication cookie, the application leaks the internal error...
Moderate
Unreviewed
CVE-2022-26070
was published
May 7, 2022
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain...
Moderate
Unreviewed
CVE-2013-6879
was published
May 5, 2022
A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0...
Moderate
Unreviewed
CVE-2021-43206
was published
May 5, 2022
htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to...
Moderate
Unreviewed
CVE-2000-1191
was published
Apr 30, 2022
An information disclosure vulnerability was discovered in glusterfs server. An attacker could...
Moderate
Unreviewed
CVE-2018-10913
was published
Apr 30, 2022
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0...
Moderate
Unreviewed
CVE-2021-39033
was published
Apr 20, 2022
Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14...
Moderate
Unreviewed
CVE-2022-1120
was published
Apr 5, 2022
Path Disclosure within joomla/filesystem class
Moderate
CVE-2022-23794
was published
for
joomla/filesystem
(Composer)
Mar 31, 2022
Path traversal allows leaking out-of-bound files from Argo CD repo-server
Moderate
CVE-2022-24731
was published
for
github.com/argoproj/argo-cd
(Go)
Mar 24, 2022
Sensitive information could be displayed when a detailed technical error message is posted. This...
Moderate
Unreviewed
CVE-2021-35251
was published
Mar 11, 2022
An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote...
Moderate
Unreviewed
CVE-2021-46353
was published
Mar 5, 2022
Ansible discloses sensitive information in traceback error message
Moderate
CVE-2021-3620
was published
for
ansible
(pip)
Mar 4, 2022
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support....
Moderate
Unreviewed
CVE-2022-0563
was published
Feb 22, 2022
Generation of Error Message Containing Sensitive Information in Snipe-IT
Moderate
CVE-2022-0622
was published
for
snipe/snipe-it
(Composer)
Feb 18, 2022
Generation of Error Message Containing Sensitive Information in postgresql
Moderate
Unreviewed
CVE-2021-3393
was published
Feb 15, 2022
Wildfly logs plaintext passwords
Moderate
CVE-2020-25640
was published
for
org.wildfly:wildfly-parent
(Maven)
Feb 15, 2022
Generation of Error Message Containing Sensitive Information in microweber
Moderate
CVE-2022-0504
was published
for
microweber/microweber
(Composer)
Feb 9, 2022
Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that...
Moderate
Unreviewed
CVE-2021-40338
was published
Jan 29, 2022
User enumeration in livehelperchat
Moderate
CVE-2022-0083
was published
for
remdex/livehelperchat
(Composer)
Jan 21, 2022
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain...
Moderate
Unreviewed
CVE-2021-38894
was published
Jan 11, 2022
ProTip!
Advisories are also available from the
GraphQL API