GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is...
Critical
Unreviewed
CVE-2018-11716
was published
May 14, 2022
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access...
Critical
Unreviewed
CVE-2018-11717
was published
May 14, 2022
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before...
Critical
Unreviewed
CVE-2018-16049
was published
May 14, 2022
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an...
Critical
Unreviewed
CVE-2018-0042
was published
May 13, 2022
Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain...
Critical
Unreviewed
CVE-2017-9615
was published
May 13, 2022
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x...
Critical
Unreviewed
CVE-2017-4955
was published
May 13, 2022
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache)...
Critical
Unreviewed
CVE-2017-15366
was published
May 13, 2022
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an...
Critical
Unreviewed
CVE-2017-6709
was published
May 13, 2022
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations...
Critical
Unreviewed
CVE-2017-7434
was published
May 13, 2022
The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver...
Critical
Unreviewed
CVE-2017-9278
was published
May 13, 2022
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored...
Critical
Unreviewed
CVE-2018-17922
was published
May 13, 2022
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log...
Critical
Unreviewed
CVE-2018-1072
was published
May 13, 2022
Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part...
Critical
Unreviewed
CVE-2018-1264
was published
May 13, 2022
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in...
Critical
Unreviewed
CVE-2019-4008
was published
May 13, 2022
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1...
Critical
Unreviewed
CVE-2019-7612
was published
May 13, 2022
Ansible Insertion of Sensitive Information into Log File vulnerability
Critical
CVE-2017-7550
was published
for
ansible
(pip)
May 13, 2022
GitHub personal access token leaking into temporary EasyBuild (debug) logs
Critical
CVE-2020-5262
was published
for
easybuild-framework
(pip)
Mar 19, 2020
Potential to access user credentials from the log files when debug logging enabled
Critical
CVE-2019-10212
was published
for
io.undertow:undertow-core
(Maven)
Nov 20, 2019
Credential exposure through log files in Undertow
Critical
CVE-2019-3888
was published
for
io.undertow:undertow-core
(Maven)
Jun 13, 2019
ProTip!
Advisories are also available from the
GraphQL API