GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,340
Erlang
31
GitHub Actions
22
Go
2,101
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
885
Swift
37
Unreviewed advisories
All unreviewed
5,000+
771 advisories
Filter by severity
Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some...
Moderate
Unreviewed
CVE-2024-48852
was published
Jan 29, 2025
kube-audit-rest's example logging configuration could disclose secret values in the audit log
Moderate
CVE-2025-24884
was published
for
github.com/RichardoC/kube-audit-rest
(Go)
Jan 29, 2025
Infinispan vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-0736
was published
for
org.infinispan:infinispan-parent
(Maven)
Jan 28, 2025
Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)...
Moderate
Unreviewed
CVE-2025-24389
was published
Jan 27, 2025
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2...
Moderate
Unreviewed
CVE-2023-38271
was published
Jan 25, 2025
GitHub PAT written to debug artifacts
High
CVE-2025-24362
was published
for
github/codeql-action
(GitHub Actions)
Jan 24, 2025
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
Moderate
Unreviewed
CVE-2025-24457
was published
Jan 21, 2025
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13...
Moderate
Unreviewed
CVE-2024-45091
was published
Jan 21, 2025
Under certain log settings the IAM or CORE service will log credentials in the iam logfile in...
Moderate
Unreviewed
CVE-2024-11923
was published
Jan 18, 2025
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be...
Moderate
Unreviewed
CVE-2024-12226
was published
Jan 16, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21316
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21320
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21319
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21317
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21321
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21318
was published
Jan 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21323
was published
Jan 14, 2025
TYPO3 Information Disclosure via Exception Handling/Logger
Low
CVE-2024-55891
was published
for
typo3/cms-install
(Composer)
Jan 14, 2025
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an...
Moderate
Unreviewed
CVE-2024-40679
was published
Jan 8, 2025
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive...
Critical
Unreviewed
CVE-2025-22275
was published
Jan 3, 2025
Disclosure of sensitive information in HikVision camera driver's log file in XProtect Device Pack...
Moderate
Unreviewed
CVE-2024-12569
was published
Dec 19, 2024
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially...
Moderate
Unreviewed
CVE-2024-49816
was published
Dec 17, 2024
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6...
Moderate
Unreviewed
CVE-2024-12292
was published
Dec 12, 2024
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app...
Moderate
Unreviewed
CVE-2024-54484
was published
Dec 12, 2024
Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm...
High
Unreviewed
CVE-2024-42407
was published
Dec 12, 2024
ProTip!
Advisories are also available from the
GraphQL API