GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,128 advisories
Filter by severity
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0...
Moderate
Unreviewed
CVE-2026-46467
was published
Jul 3, 2026
A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0...
Moderate
Unreviewed
CVE-2026-8482
was published
Jul 2, 2026
Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information...
Moderate
Unreviewed
CVE-2026-49088
was published
Jul 1, 2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM...
Moderate
Unreviewed
CVE-2026-12086
was published
Jun 30, 2026
Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed...
Moderate
Unreviewed
CVE-2026-13750
was published
Jun 29, 2026
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information...
Moderate
Unreviewed
CVE-2026-56457
was published
Jun 29, 2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure...
Moderate
Unreviewed
CVE-2025-59868
was published
Jun 27, 2026
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
Moderate
GHSA-q683-8468-r6h6
was published
for
web-auth/webauthn-symfony-bundle
(Composer)
Jun 26, 2026
Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from...
Moderate
Unreviewed
CVE-2026-9699
was published
Jun 26, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19...
Moderate
Unreviewed
CVE-2026-8330
was published
Jun 25, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that...
High
Unreviewed
CVE-2026-12053
was published
Jun 25, 2026
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms...
Moderate
Unreviewed
CVE-2026-9073
was published
Jun 23, 2026
Module: plugins/modules/nexmo.py
CVSS 3.1: 6.5 MEDIUM — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
...
Moderate
Unreviewed
CVE-2026-11820
was published
Jun 23, 2026
Module: plugins/modules/keyring_info.py
CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N...
Moderate
Unreviewed
CVE-2026-11819
was published
Jun 23, 2026
PGHoard: Password written to debug log
Low
CVE-2026-54711
was published
for
pghoard
(pip)
Jun 18, 2026
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
Moderate
CVE-2026-54236
was published
for
vllm
(pip)
Jun 17, 2026
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26...
Moderate
Unreviewed
CVE-2025-46313
was published
Jun 11, 2026
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS...
Moderate
Unreviewed
CVE-2026-0267
was published
Jun 11, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
Moderate
CVE-2026-47768
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 10, 2026
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the...
Moderate
Unreviewed
CVE-2026-9751
was published
Jun 10, 2026
MongoDB server may log authentication parameters, including credentials, to the server log during...
Moderate
Unreviewed
CVE-2026-9735
was published
Jun 10, 2026
System log files output unencrypted SMTP server authentication passwords alongside sensitive...
High
Unreviewed
CVE-2026-50205
was published
Jun 4, 2026
A high security vulnerability affecting Security Center main server installations has been...
High
Unreviewed
CVE-2026-40619
was published
Jun 2, 2026
Admidio writes session IDs and auto-login cookie values to application logs
Moderate
CVE-2026-47234
was published
for
admidio/admidio
(Composer)
May 29, 2026
The acer_cgi.log file in the device firmware is accessible without authentication via the web...
Critical
Unreviewed
CVE-2026-49200
was published
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API