GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
518 advisories
Filter by severity
Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers
Moderate
GHSA-xvp7-8vm8-xfxx
was published
for
@actual-app/sync-server
(npm)
Oct 20, 2025
ibexa/user login enumerates user accounts
Moderate
GHSA-q3x8-6898-23g3
was published
for
ibexa/user
(Composer)
Oct 17, 2025
Generation of error message containing sensitive information in Windows USB Video Driver allows...
Moderate
Unreviewed
CVE-2025-55676
was published
Oct 14, 2025
HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes...
Low
Unreviewed
CVE-2025-31998
was published
Oct 12, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Get Function
Moderate
CVE-2025-54291
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Dell Crypto-J generates an error message that includes sensitive information about its...
Moderate
Unreviewed
CVE-2025-26333
was published
Sep 25, 2025
Generation of error message containing sensitive information in Windows Kernel allows an...
Moderate
Unreviewed
CVE-2025-53803
was published
Sep 9, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
Moderate
CVE-2025-43776
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 9, 2025
TYPO3 CMS exposes sensitive information in an error message
Moderate
CVE-2025-59016
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
Liferay Portal exposes 500 status when attempting login with a deleted client secret
Moderate
CVE-2025-43777
was published
for
com.liferay:com.liferay.portal.security.sso.openid.connect.impl
(Maven)
Sep 9, 2025
In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a...
Moderate
Unreviewed
CVE-2025-48562
was published
Sep 4, 2025
IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain...
High
Unreviewed
CVE-2025-36003
was published
Aug 28, 2025
Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0...
Moderate
Unreviewed
CVE-2025-9229
was published
Aug 20, 2025
HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under...
Moderate
Unreviewed
CVE-2025-52619
was published
Aug 16, 2025
OMERO.web displays unecessary user information when requesting password reset
Moderate
CVE-2025-54791
was published
for
omero-web
(pip)
Aug 13, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
Low
Unreviewed
CVE-2024-41984
was published
Aug 12, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
Moderate
Unreviewed
CVE-2024-41983
was published
Aug 12, 2025
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part...
Moderate
Unreviewed
CVE-2025-8852
was published
Aug 11, 2025
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python...
High
Unreviewed
CVE-2025-23320
was published
Aug 6, 2025
An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error...
Critical
Unreviewed
CVE-2025-46658
was published
Aug 5, 2025
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the...
Moderate
Unreviewed
CVE-2025-47813
was published
Jul 10, 2025
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain...
Moderate
Unreviewed
CVE-2025-36090
was published
Jul 10, 2025
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain...
Moderate
Unreviewed
CVE-2024-37524
was published
Jul 10, 2025
Improper error handling vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter....
Moderate
Unreviewed
CVE-2025-40718
was published
Jul 8, 2025
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2025-5731
was published
for
org.infinispan:infinispan-cli-client
(Maven)
Jun 27, 2025
ProTip!
Advisories are also available from the
GraphQL API