GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
306 advisories
Filter by severity
Sentry improper error handling leaks Application Integration Client Secret
Moderate
CVE-2024-53253
was published
for
sentry
(pip)
Nov 22, 2024
jupyter-server errors include tracebacks with path information
Moderate
CVE-2023-49080
was published
for
jupyter-server
(pip)
Dec 5, 2023
Generation of Error Message Containing Sensitive Information in janeczku/calibre-web
Moderate
CVE-2021-3986
was published
for
calibreweb
(pip)
Nov 15, 2024
Weblate user account enumeration via reset password form
Moderate
CVE-2017-5537
was published
for
weblate
(pip)
May 17, 2022
Moodle leaks user names
Moderate
CVE-2024-48896
was published
for
moodle/moodle
(Composer)
Nov 18, 2024
Grafana User enumeration via forget password
High
CVE-2022-39307
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
Flask-AppBuilder vulnerable to possible disclosure of sensitive information on user error
Moderate
CVE-2023-34110
was published
for
Flask-AppBuilder
(pip)
Jun 22, 2023
The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not...
Unknown
Unreviewed
CVE-2023-40457
was published
Nov 11, 2024
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs...
High
Unreviewed
CVE-2024-51560
was published
Nov 4, 2024
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive...
Moderate
Unreviewed
CVE-2024-30141
was published
Nov 7, 2024
In the Linux kernel, the following vulnerability has been resolved:
spi: spi-fsl-dspi: Fix a...
Moderate
Unreviewed
CVE-2021-47161
was published
Mar 25, 2024
Exposure of secrets through system log in Jenkins Structs Plugin
Low
CVE-2024-39458
was published
for
org.jenkins-ci.plugins:structs
(Maven)
Jun 26, 2024
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api...
High
Unreviewed
CVE-2024-39719
was published
Oct 31, 2024
Generation of Error Message Containing Sensitive Information in zsa
Moderate
CVE-2024-37162
was published
for
zsa
(npm)
Jun 6, 2024
Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti...
Moderate
Unreviewed
CVE-2024-50512
was published
Oct 30, 2024
Drupal Full Path Disclosure
Moderate
CVE-2024-45440
was published
for
drupal/core
(Composer)
Aug 29, 2024
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can...
Low
Unreviewed
CVE-2023-50355
was published
Oct 24, 2024
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows...
Moderate
Unreviewed
CVE-2024-44762
was published
Oct 16, 2024
SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non...
Moderate
Unreviewed
CVE-2024-45713
was published
Oct 17, 2024
open-webui allows enumeration of file names and traversal of directories by observing the error messages
Low
CVE-2024-7038
was published
for
open-webui
(pip)
Oct 9, 2024
Exposure of Sensitive Information in OPC UA .NET Standard Reference Server
Moderate
CVE-2023-31048
was published
for
OPCFoundation.NetStandard.Opc.Ua.Core
(NuGet)
May 5, 2023
Possible leak of key's raw field if declared length is incorrect
Moderate
CVE-2022-31124
was published
for
openssh-key-parser
(pip)
Jul 6, 2022
OpenStack Nova Server Resource Faults Leak External Exception Details
High
CVE-2019-14433
was published
for
nova
(pip)
May 24, 2022
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full...
Moderate
Unreviewed
CVE-2024-6551
was published
Aug 29, 2024
Apache Superset: Improper error handling on alerts
Moderate
CVE-2024-27315
was published
for
apache-superset
(pip)
Feb 28, 2024
ProTip!
Advisories are also available from the
GraphQL API