GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,082
Maven
5,000+
npm
3,747
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
466 advisories
Filter by severity
A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA...
Moderate
Unreviewed
CVE-2024-45102
was published
Jan 15, 2025
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology...
Moderate
Unreviewed
CVE-2021-26565
was published
May 24, 2022
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation...
Moderate
Unreviewed
CVE-2020-27656
was published
May 24, 2022
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. ...
Low
Unreviewed
CVE-2024-42181
was published
Jan 13, 2025
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to...
Moderate
Unreviewed
CVE-2021-39090
was published
Feb 29, 2024
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive...
Low
Unreviewed
CVE-2024-11946
was published
Dec 30, 2024
IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms...
Moderate
Unreviewed
CVE-2021-39081
was published
Dec 19, 2024
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote...
Low
Unreviewed
CVE-2024-49820
was published
Dec 17, 2024
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote...
Moderate
Unreviewed
CVE-2024-49819
was published
Dec 17, 2024
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions...
Moderate
Unreviewed
CVE-2024-53246
was published
Dec 10, 2024
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information...
Low
Unreviewed
CVE-2024-47577
was published
Dec 10, 2024
Web browser interface may manipulate application username/password in clear text or Base64...
High
Unreviewed
CVE-2024-6515
was published
Dec 5, 2024
IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2021-29892
was published
Dec 3, 2024
In affected versions of Octopus Server under certain circumstances it is possible for sensitive...
Moderate
Unreviewed
CVE-2024-6972
was published
Jul 25, 2024
Improper data protection on the ventilator's serial interface could allow an attacker to send and...
Critical
Unreviewed
CVE-2024-9834
was published
Nov 14, 2024
Cleartext transmission of sensitive information for some BigDL software maintained by Intel(R)...
Moderate
Unreviewed
CVE-2024-28169
was published
Nov 13, 2024
A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform...
High
Unreviewed
CVE-2024-50634
was published
Nov 8, 2024
Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may...
Moderate
Unreviewed
CVE-2024-0066
was published
Jun 18, 2024
An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge...
High
Unreviewed
CVE-2022-32510
was published
May 14, 2024
It is possible for an API key to be logged in clear text in the audit log file after an invalid...
Moderate
Unreviewed
CVE-2023-4509
was published
Apr 18, 2024
ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of...
Moderate
Unreviewed
CVE-2024-50624
was published
Oct 28, 2024
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0...
Moderate
Unreviewed
CVE-2024-35495
was published
Sep 30, 2024
A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive...
Moderate
Unreviewed
CVE-2024-32946
was published
Oct 30, 2024
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can...
Critical
Unreviewed
CVE-2024-25735
was published
Mar 27, 2024
A bug in query analysis of certain complex self-referential $lookup subpipelines may result in...
Low
Unreviewed
CVE-2024-8013
was published
Oct 28, 2024
ProTip!
Advisories are also available from the
GraphQL API