GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
127 advisories
Filter by severity
In affected versions of Octopus Server it was identified that when a sensitive value is a...
Moderate
Unreviewed
CVE-2022-2720
was published
Oct 12, 2022
An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17...
Moderate
Unreviewed
CVE-2025-0679
was published
May 22, 2025
Sensitive device logger information in ASPECT may be exposed if administrator credentials become...
Moderate
Unreviewed
CVE-2024-13953
was published
May 22, 2025
Exposure of private personal information to an unauthorized actor in the user vaults component of...
High
Unreviewed
CVE-2025-5334
was published
May 29, 2025
A privacy issue was addressed with improved private data redaction for log entries. This issue is...
Low
Unreviewed
CVE-2023-42830
was published
Jan 11, 2024
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack...
High
Unreviewed
CVE-2025-49715
was published
Jun 20, 2025
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2...
Moderate
Unreviewed
CVE-2025-6017
was published
Jul 2, 2025
DynamicPageList3 vulnerability exposes hidden/suppressed usernames
High
CVE-2025-53625
was published
for
universal-omega/dynamic-page-list3
(Composer)
Jul 10, 2025
Weblate exposes personal IP address via e-mail
Low
CVE-2025-49134
was published
for
weblate
(pip)
Jun 16, 2025
XWiki leaks password hashes and other accessible password properties
High
CVE-2025-54124
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Aug 5, 2025
XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
High
CVE-2025-54125
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Aug 5, 2025
Exposure of private personal information to an unauthorized actor in Azure Stack allows an...
Moderate
Unreviewed
CVE-2025-53765
was published
Aug 12, 2025
A low-privileged remote attacker can obtain the username of another registered Sunny Portal user...
Moderate
Unreviewed
CVE-2025-41685
was published
Aug 19, 2025
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user...
High
Unreviewed
CVE-2024-7697
was published
Aug 12, 2024
Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to...
High
Unreviewed
CVE-2024-11206
was published
Nov 14, 2024
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition...
Low
Unreviewed
CVE-2025-1939
was published
Mar 4, 2025
Presta Shop vulnerable to email enumeration
Moderate
CVE-2025-51586
was published
for
prestashop/prestashop
(Composer)
Sep 4, 2025
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing...
Moderate
Unreviewed
CVE-2025-10859
was published
Sep 30, 2025
In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire...
Low
Unreviewed
CVE-2025-5009
was published
Oct 8, 2025
Withdrawn Advisory: Incorrect Authorization in cross-fetch
Moderate
CVE-2022-1365
was published
for
cross-fetch
(npm)
Apr 17, 2022
•
withdrawn
An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in...
Moderate
Unreviewed
CVE-2025-53950
was published
Oct 16, 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global...
Moderate
Unreviewed
CVE-2025-62644
was published
Oct 17, 2025
Mattermost Server: initial_load API exposes unnecessary information
High
CVE-2016-11066
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre...
Moderate
Unreviewed
CVE-2025-35981
was published
Oct 23, 2025
This issue was addressed with improved redaction of sensitive information. This issue is fixed in...
Moderate
Unreviewed
CVE-2025-43259
was published
Jul 30, 2025
ProTip!
Advisories are also available from the
GraphQL API