GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,124
Maven
5,000+
npm
3,787
NuGet
683
pip
3,467
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
398 advisories
Filter by severity
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to...
Moderate
Unreviewed
CVE-2023-38362
was published
Mar 4, 2024
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to...
Moderate
Unreviewed
CVE-2023-27283
was published
May 4, 2024
emoncms v11 and later was discovered to contain an information disclosure vulnerability which...
Moderate
Unreviewed
CVE-2023-33518
was published
Jun 5, 2023
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0....
Moderate
Unreviewed
CVE-2024-13198
was published
Jan 9, 2025
When dragging and dropping an image cross-origin, the image's size could potentially be leaked....
Moderate
Unreviewed
CVE-2023-25741
was published
Jun 2, 2023
The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a...
Moderate
Unreviewed
CVE-2023-25728
was published
Jun 2, 2023
Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device...
Moderate
Unreviewed
CVE-2022-24695
was published
Jun 2, 2023
OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution...
Moderate
Unreviewed
CVE-2023-24598
was published
May 29, 2023
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that...
Moderate
Unreviewed
CVE-2023-26215
was published
May 25, 2023
The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability...
Moderate
Unreviewed
CVE-2023-28015
was published
Jul 6, 2023
Gradio performs a non-constant-time comparison when comparing hashes
Moderate
CVE-2024-47869
was published
for
gradio
(pip)
Oct 10, 2024
In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error...
Moderate
Unreviewed
CVE-2024-43763
was published
Jan 22, 2025
In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an...
Moderate
Unreviewed
CVE-2024-49733
was published
Jan 22, 2025
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13...
Moderate
Unreviewed
CVE-2023-27931
was published
May 8, 2023
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2023-28200
was published
May 8, 2023
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition...
Moderate
Unreviewed
CVE-2024-45089
was published
Jan 31, 2025
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through...
Moderate
Unreviewed
CVE-2024-36510
was published
Jan 14, 2025
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to...
Moderate
Unreviewed
CVE-2023-26560
was published
Apr 26, 2023
A specific authentication strategy allows to learn ids of PAM users associated with certain...
Moderate
Unreviewed
CVE-2025-24506
was published
Jan 30, 2025
front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access...
Moderate
Unreviewed
CVE-2022-34125
was published
Apr 16, 2023
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite,...
Moderate
Unreviewed
CVE-2020-35165
was published
May 22, 2024
The login functionality of the web server in affected devices does not normalize the response...
Moderate
Unreviewed
CVE-2023-37482
was published
Feb 11, 2025
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable...
Moderate
Unreviewed
CVE-2023-50306
was published
Feb 20, 2024
ProTip!
Advisories are also available from the
GraphQL API