GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,270
Erlang
31
GitHub Actions
21
Go
2,046
Maven
5,000+
npm
3,737
NuGet
663
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
541 advisories
Filter by severity
Windows Printing Service Spoofing Vulnerability
High
Unreviewed
CVE-2024-21406
was published
Feb 13, 2024
All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config...
High
Unreviewed
CVE-2022-47892
was published
Oct 3, 2023
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP ...
Critical
Unreviewed
CVE-2019-17393
was published
May 24, 2022
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to...
Moderate
Unreviewed
CVE-2020-14171
was published
May 24, 2022
In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using...
High
Unreviewed
CVE-2022-42916
was published
Oct 29, 2022
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking...
High
Unreviewed
CVE-2021-22946
was published
May 24, 2022
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure...
Moderate
Unreviewed
CVE-2022-30115
was published
Jun 3, 2022
dectalk-tts Uses Unencrypted HTTP Request
High
CVE-2024-31206
was published
for
dectalk-tts
(npm)
Apr 4, 2024
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment...
High
Unreviewed
CVE-2023-38276
was published
Oct 22, 2023
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container...
High
Unreviewed
CVE-2023-38275
was published
Oct 22, 2023
The affected product is vulnerable to a cleartext transmission of sensitive...
Moderate
Unreviewed
CVE-2023-41088
was published
Oct 19, 2023
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a cleartext...
High
Unreviewed
CVE-2023-34441
was published
Oct 19, 2023
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an...
High
Unreviewed
CVE-2022-22385
was published
Oct 17, 2023
Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an
unprivileged...
Moderate
Unreviewed
CVE-2023-5100
was published
Oct 9, 2023
A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN...
Moderate
Unreviewed
CVE-2023-23371
was published
Oct 6, 2023
A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra...
High
Unreviewed
CVE-2023-3361
was published
Oct 4, 2023
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which...
High
Unreviewed
CVE-2023-43124
was published
Sep 27, 2023
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which...
High
Unreviewed
CVE-2023-43125
was published
Sep 27, 2023
An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the...
High
Unreviewed
CVE-2023-42147
was published
Sep 20, 2023
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages...
High
Unreviewed
CVE-2022-3261
was published
Sep 15, 2023
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected...
High
Unreviewed
CVE-2023-40729
was published
Sep 14, 2023
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation...
High
Unreviewed
CVE-2023-34998
was published
Sep 5, 2023
IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by...
Moderate
Unreviewed
CVE-2023-22870
was published
Sep 5, 2023
ArcGIS Enterprise Server versions 11.0 and below have an information disclosure...
Moderate
Unreviewed
CVE-2023-25848
was published
Aug 25, 2023
A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP...
Moderate
Unreviewed
CVE-2023-34972
was published
Aug 24, 2023
ProTip!
Advisories are also available from the
GraphQL API