GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,697
Erlang
34
GitHub Actions
28
Go
2,289
Maven
5,000+
npm
3,936
NuGet
708
pip
3,706
Pub
12
RubyGems
919
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
170 advisories
Filter by severity
Milestone Systems has discovered a
security vulnerability in Milestone XProtect installer that...
Moderate
Unreviewed
CVE-2025-1688
was published
Apr 15, 2025
Jenkins AsakusaSatellite Plugin Does not Mask API Keys via Job Configuration Form
Moderate
CVE-2025-31728
was published
for
org.codefirst.jenkins.asakusasatellite:asakusa-satellite-plugin
(Maven)
Apr 2, 2025
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2...
Moderate
Unreviewed
CVE-2023-37405
was published
Mar 27, 2025
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI
could allow a remote...
Moderate
Unreviewed
CVE-2024-38325
was published
Jan 27, 2025
IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2024-41757
was published
Jan 24, 2025
On Arista CloudVision Appliance (CVA) affected releases running on appliances that support...
Moderate
Unreviewed
CVE-2024-7142
was published
Jan 11, 2025
Snowflake JDBC Security Advisory
Moderate
CVE-2024-43382
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Oct 30, 2024
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE)...
Moderate
Unreviewed
CVE-2024-20515
was published
Oct 2, 2024
Missing encryption of sensitive data vulnerability in login component in Synology Active Backup...
Moderate
Unreviewed
CVE-2023-52950
was published
Sep 26, 2024
Missing encryption of sensitive data vulnerability in settings functionality in Synology Active...
Moderate
Unreviewed
CVE-2023-52948
was published
Sep 26, 2024
A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to...
Moderate
Unreviewed
CVE-2024-20503
was published
Sep 4, 2024
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to...
Moderate
Unreviewed
CVE-2024-39746
was published
Aug 22, 2024
IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2024-31905
was published
Aug 15, 2024
CVE-2024-40620 IMPACT
A vulnerability exists in the affected product due to lack of encryption...
Moderate
Unreviewed
CVE-2024-40620
was published
Aug 14, 2024
Elasticsearch stores private key on disk unencrypted
Moderate
CVE-2024-23444
was published
for
org.elasticsearch:elasticsearch
(Maven)
Jul 31, 2024
Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data...
Moderate
Unreviewed
CVE-2024-38302
was published
Jul 18, 2024
A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow...
Moderate
Unreviewed
CVE-2024-5731
was published
Jun 14, 2024
An issue was discovered in Samsung Mobile Processor, Automotive Processor, Wearable Processor,...
Moderate
Unreviewed
CVE-2023-49927
was published
Jun 5, 2024
silverstripe/framework users inadvertently passing sensitive data to LoginAttempt
Moderate
GHSA-ph62-fv59-vf9h
was published
for
silverstripe/framework
(Composer)
May 27, 2024
Vulnerable data in transit in GE HealthCare EchoPAC products
Moderate
Unreviewed
CVE-2024-27106
was published
May 14, 2024
IBM Security Verify Access 10.0.6 could disclose sensitive snapshot information due to missing...
Moderate
Unreviewed
CVE-2024-25027
was published
Mar 31, 2024
IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2023-35888
was published
Mar 20, 2024
Unencrypted traffic between nodes when using WireGuard and L7 policies
Moderate
CVE-2024-28250
was published
for
github.com/cilium/cilium
(Go)
Mar 18, 2024
Unencrypted traffic between nodes when using IPsec and L7 policies
Moderate
CVE-2024-28249
was published
for
github.com/cilium/cilium
(Go)
Mar 18, 2024
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical...
Moderate
Unreviewed
CVE-2023-27291
was published
Mar 3, 2024
ProTip!
Advisories are also available from the
GraphQL API