GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
6,768 advisories
Filter by severity
Juju vulnerable to sensitive log retrieval via authenticated endpoint without authorization
Moderate
CVE-2025-53512
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Cloudflare Vite plugin exposes secrets over the built-in dev server
Moderate
CVE-2025-59427
was published
for
@cloudflare/vite-plugin
(npm)
Jul 8, 2025
Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework...
Moderate
Unreviewed
CVE-2025-49664
was published
Jul 8, 2025
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized...
Moderate
Unreviewed
CVE-2025-48808
was published
Jul 8, 2025
Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an...
Moderate
Unreviewed
CVE-2025-47980
was published
Jul 8, 2025
The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information...
Moderate
Unreviewed
CVE-2024-11089
was published
Jul 7, 2025
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form &...
Moderate
Unreviewed
CVE-2024-13451
was published
Jul 2, 2025
An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server...
Moderate
Unreviewed
CVE-2025-6600
was published
Jul 1, 2025
An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and...
Moderate
Unreviewed
CVE-2025-34052
was published
Jul 1, 2025
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5...
Moderate
Unreviewed
CVE-2025-34062
was published
Jul 1, 2025
A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR...
Moderate
Unreviewed
CVE-2025-34051
was published
Jul 1, 2025
An attacker who enumerated resources from the WebCompat extension could have obtained a...
Moderate
Unreviewed
CVE-2025-6425
was published
Jun 26, 2025
An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to...
Moderate
Unreviewed
CVE-2023-47298
was published
Jun 23, 2025
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not...
Moderate
Unreviewed
CVE-2025-49177
was published
Jun 17, 2025
The created backup files are unencrypted, making the application vulnerable for gathering...
Moderate
Unreviewed
CVE-2025-49200
was published
Jun 12, 2025
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions...
Moderate
Unreviewed
CVE-2025-4798
was published
Jun 11, 2025
In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A...
Moderate
Unreviewed
CVE-2025-30675
was published
Jun 11, 2025
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an...
Moderate
Unreviewed
CVE-2025-43579
was published
Jun 10, 2025
Nautobot may allows uploaded media files to be accessible without authentication
Moderate
CVE-2025-49143
was published
for
nautobot
(pip)
Jun 10, 2025
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized...
Moderate
Unreviewed
CVE-2025-47969
was published
Jun 10, 2025
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS...
Moderate
Unreviewed
CVE-2025-25250
was published
Jun 10, 2025
GWC Home Page communicate version and revision information
Moderate
CVE-2024-38524
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an...
Moderate
Unreviewed
CVE-2025-40662
was published
Jun 10, 2025
The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes,...
Moderate
Unreviewed
CVE-2025-25209
was published
Jun 9, 2025
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-21486
was published
for
deno
(Rust)
Jun 5, 2025
ProTip!
Advisories are also available from the
GraphQL API