GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,313
Erlang
31
GitHub Actions
21
Go
2,072
Maven
5,000+
npm
3,744
NuGet
674
pip
3,433
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
45 advisories
Filter by severity
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log...
Critical
Unreviewed
CVE-2017-8075
was published
May 17, 2022
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log...
Critical
Unreviewed
CVE-2017-8074
was published
May 17, 2022
Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may...
Critical
Unreviewed
CVE-2016-8233
was published
May 17, 2022
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade,...
Critical
Unreviewed
CVE-2019-15294
was published
May 24, 2022
In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in...
Critical
Unreviewed
CVE-2019-17396
was published
May 24, 2022
In the Orbitz application 19.31.1 for Android, the username and password are stored in the log...
Critical
Unreviewed
CVE-2019-17355
was published
May 24, 2022
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are...
Critical
Unreviewed
CVE-2019-17394
was published
May 24, 2022
In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the...
Critical
Unreviewed
CVE-2019-17398
was published
May 24, 2022
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log...
Critical
Unreviewed
CVE-2019-17395
was published
May 24, 2022
A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens...
Critical
Unreviewed
CVE-2021-3528
was published
May 24, 2022
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate...
Critical
Unreviewed
CVE-2021-37760
was published
May 24, 2022
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate...
Critical
Unreviewed
CVE-2021-37759
was published
May 24, 2022
Weave GitOps leaked cluster credentials into logs on connection errors
Critical
CVE-2022-31098
was published
for
github.com/weaveworks/weave-gitops
(Go)
Jun 23, 2022
check-spelling workflow vulnerable to token leakage via symlink attack
Critical
CVE-2021-32724
was published
for
check-spelling/check-spelling
(GitHub Actions)
Jul 29, 2022
Argo CD cluster secret might leak in cluster details page
Critical
CVE-2023-40029
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 11, 2023
If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the...
Critical
Unreviewed
CVE-2023-46668
was published
Oct 26, 2023
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion...
Critical
Unreviewed
CVE-2023-36649
was published
Dec 12, 2023
Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage...
Critical
Unreviewed
CVE-2022-36407
was published
Mar 25, 2024
@valtimo/components exposes access token to form.io
Critical
CVE-2024-34706
was published
for
@valtimo/components
(npm)
May 13, 2024
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive...
Critical
Unreviewed
CVE-2025-22275
was published
Jan 3, 2025
ProTip!
Advisories are also available from the
GraphQL API