GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,170
Erlang
30
GitHub Actions
19
Go
1,981
Maven
5,000+
npm
3,700
NuGet
656
pip
3,319
Pub
11
RubyGems
882
Rust
834
Swift
35
Unreviewed advisories
All unreviewed
5,000+
6,094 advisories
Filter by severity
In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to...
Moderate
Unreviewed
CVE-2021-0321
was published
May 24, 2022
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and...
Moderate
Unreviewed
CVE-2021-25230
was published
May 24, 2022
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and...
Moderate
Unreviewed
CVE-2021-25232
was published
May 24, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
Moderate
CVE-2012-5055
was published
for
org.springframework.security:spring-security-core
(Maven)
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in OpenSAML
Moderate
CVE-2013-6440
was published
for
org.opensaml:opensaml
(Maven)
May 13, 2022
An exploitable local information leak vulnerability exists in the privileged helper tool of GOG...
Moderate
Unreviewed
CVE-2018-4052
was published
May 13, 2022
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows...
Moderate
Unreviewed
CVE-2022-36834
was published
Aug 6, 2022
GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing...
Moderate
Unreviewed
CVE-2020-10087
was published
May 24, 2022
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs)....
Moderate
Unreviewed
CVE-2017-10379
was published
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2018-1000068
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be...
Moderate
Unreviewed
CVE-2022-28774
was published
May 12, 2022
An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module...
Moderate
Unreviewed
CVE-2019-5017
was published
May 24, 2022
Exposure of Sensitive Information to an Unauthorized Actor in JGroup
Moderate
CVE-2013-4112
was published
for
org.jgroups:jgroups
(Maven)
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2017-1000395
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2017-1000398
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
Moderate
CVE-2016-6345
was published
for
org.jboss.resteasy:resteasy-client
(Maven)
May 17, 2022
Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to...
Moderate
Unreviewed
CVE-2018-20237
was published
May 13, 2022
Phusion Passenger information disclosure
Moderate
CVE-2017-16355
was published
for
passenger
(RubyGems)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Undertow
Moderate
CVE-2018-14642
was published
for
io.undertow:undertow-core
(Maven)
May 13, 2022
Improper Certificate Handling
Moderate
CVE-2020-9321
was published
for
github.com/traefik/traefik
(Go)
Sep 2, 2021
Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java
Moderate
CVE-2017-3586
was published
for
mysql:mysql-connector-java
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2017-2609
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin
Moderate
CVE-2017-1000505
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2018-1000192
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Moderate
CVE-2015-1776
was published
for
org.apache.hadoop:hadoop-common
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API