GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
738 advisories
Filter by severity
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to...
High
Unreviewed
CVE-2019-9976
was published
May 13, 2022
RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users'...
Moderate
Unreviewed
CVE-2019-3715
was published
May 13, 2022
RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The...
High
Unreviewed
CVE-2019-3716
was published
May 13, 2022
Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS...
High
Unreviewed
CVE-2019-0266
was published
May 13, 2022
Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users....
High
Unreviewed
CVE-2019-0029
was published
May 13, 2022
The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16...
Moderate
Unreviewed
CVE-2018-7754
was published
May 13, 2022
A plain keystore password is written to a system log file in SAP HANA Extended Application...
Moderate
Unreviewed
CVE-2018-2372
was published
May 13, 2022
** DISPUTED ** An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode...
High
Unreviewed
CVE-2018-18466
was published
May 13, 2022
In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a...
Moderate
Unreviewed
CVE-2018-16095
was published
May 13, 2022
Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7...
High
Unreviewed
CVE-2018-15797
was published
May 13, 2022
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly...
High
Unreviewed
CVE-2018-3827
was published
May 13, 2022
A password management issue exists where the Organization authentication username and password...
High
Unreviewed
CVE-2019-0032
was published
May 13, 2022
On Juniper ATP, the API key and the device key are logged in a file readable by authenticated...
Moderate
Unreviewed
CVE-2019-0004
was published
May 13, 2022
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1...
Critical
Unreviewed
CVE-2019-7612
was published
May 13, 2022
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat...
High
Unreviewed
CVE-2019-3891
was published
May 13, 2022
(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the...
Low
Unreviewed
CVE-2013-6384
was published
May 13, 2022
Ceilometer Prints Sensitive Configuration Data to Log
Moderate
CVE-2019-3830
was published
for
ceilometer
(pip)
May 13, 2022
The commandline package update tool zypper writes HTTP proxy credentials into its logfile,...
Low
Unreviewed
CVE-2017-9271
was published
May 13, 2022
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful...
Moderate
Unreviewed
CVE-2018-7682
was published
May 13, 2022
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive...
High
Unreviewed
CVE-2018-7683
was published
May 13, 2022
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI...
High
Unreviewed
CVE-2016-9882
was published
May 13, 2022
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 ...
Moderate
Unreviewed
CVE-2019-8944
was published
May 13, 2022
Openstack Octavia allows Insertion of Sensitive Information into Log File
High
CVE-2018-16856
was published
for
octavia
(pip)
May 13, 2022
Ansible Insertion of Sensitive Information into Log File vulnerability
Critical
CVE-2017-7550
was published
for
ansible
(pip)
May 13, 2022
The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0...
Low
Unreviewed
CVE-2011-1943
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API