GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,722
Maven
5,000+
npm
4,329
NuGet
762
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
562 advisories
Filter by severity
Medtronic CareLink Network allows a local attacker with access to log files on an internal API...
Moderate
Unreviewed
CVE-2025-12996
was published
Dec 4, 2025
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC...
Moderate
Unreviewed
CVE-2025-54971
was published
Nov 18, 2025
Insertion of sensitive information into log file in Windows License Manager allows an authorized...
Moderate
Unreviewed
CVE-2025-62208
was published
Nov 11, 2025
Insertion of sensitive information into log file in Windows License Manager allows an authorized...
Moderate
Unreviewed
CVE-2025-62209
was published
Nov 11, 2025
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and...
Moderate
Unreviewed
CVE-2025-43426
was published
Nov 4, 2025
A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances...
Moderate
Unreviewed
CVE-2025-40603
was published
Oct 31, 2025
Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature
Moderate
CVE-2025-62262
was published
for
com.liferay:com.liferay.portal.security.ldap.impl
(Maven)
Oct 27, 2025
Rancher exposes sensitive information through audit logs
Moderate
CVE-2024-58269
was published
for
github.com/rancher/rancher
(Go)
Oct 24, 2025
OpenBao and Vault Leak []byte Fields in Audit Logs
Moderate
CVE-2025-62705
was published
for
github.com/openbao/openbao
(Go)
Oct 22, 2025
OpenBao leaks HTTPRawBody in Audit Logs
Moderate
CVE-2025-62513
was published
for
github.com/openbao/openbao
(Go)
Oct 22, 2025
A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11...
Moderate
Unreviewed
CVE-2025-46752
was published
Oct 16, 2025
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and...
Moderate
Unreviewed
CVE-2025-20329
was published
Oct 15, 2025
The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2025-10486
was published
Oct 15, 2025
Insertion of sensitive information into log file in Active Directory Federation Services allows...
Moderate
Unreviewed
CVE-2025-59258
was published
Oct 14, 2025
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized...
Moderate
Unreviewed
CVE-2025-59197
was published
Oct 14, 2025
Insertion of sensitive information into log file in Windows StateRepository API allows an...
Moderate
Unreviewed
CVE-2025-59203
was published
Oct 14, 2025
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized...
Moderate
Unreviewed
CVE-2025-47979
was published
Oct 14, 2025
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Moderate
CVE-2025-37727
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 10, 2025
The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
Moderate
Unreviewed
CVE-2025-10645
was published
Oct 7, 2025
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information...
Moderate
Unreviewed
CVE-2025-9985
was published
Sep 26, 2025
A logging issue was addressed with improved data redaction. This issue is fixed in tvOS 26,...
Moderate
Unreviewed
CVE-2025-43354
was published
Sep 16, 2025
A logging issue was addressed with improved data redaction. This issue is fixed in tvOS 26,...
Moderate
Unreviewed
CVE-2025-43303
was published
Sep 16, 2025
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in...
Moderate
Unreviewed
CVE-2025-10221
was published
Sep 10, 2025
secrets-store-sync-controller discloses service account tokens in logs
Moderate
CVE-2025-7445
was published
for
sigs.k8s.io/secrets-store-sync-controller
(Go)
Sep 5, 2025
NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are...
Moderate
Unreviewed
CVE-2025-23261
was published
Sep 5, 2025
ProTip!
Advisories are also available from the
GraphQL API