GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,782
NuGet
683
pip
3,460
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,060 advisories
Filter by severity
A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web...
High
Unreviewed
CVE-2024-46437
was published
Feb 10, 2025
A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-1115
was published
Feb 8, 2025
SQL injection in JeecgBoot
High
CVE-2024-57606
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Feb 8, 2025
An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via...
High
Unreviewed
CVE-2024-55272
was published
Feb 8, 2025
Connect-CMS information that is restricted to viewing is visible
High
GHSA-2237-5r9w-vm8j
was published
for
opensource-workshop/connect-cms
(Composer)
Feb 7, 2025
An information disclosure vulnerability exists in the Vault API functionality of ClearML...
High
Unreviewed
CVE-2024-43779
was published
Feb 6, 2025
Permission verification vulnerability in the media library module
Impact: Successful exploitation...
Moderate
Unreviewed
CVE-2024-57954
was published
Feb 6, 2025
Arbitrary write vulnerability in the Gallery module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2024-57955
was published
Feb 6, 2025
A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and...
Moderate
Unreviewed
CVE-2025-20207
was published
Feb 5, 2025
The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for...
Moderate
Unreviewed
CVE-2024-13829
was published
Feb 5, 2025
Grafana Alerting VictorOps integration could be exposed to users with Viewer permission
Moderate
CVE-2024-11741
was published
for
github.com/grafana/grafana
(Go)
Jan 31, 2025
PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext
Low
CVE-2025-23215
was published
for
net.sourceforge.pmd:pmd-core
(Maven)
Jan 31, 2025
The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information...
Moderate
Unreviewed
CVE-2024-13623
was published
Jan 31, 2025
Argo CD does not scrub secret values from patch errors
Moderate
CVE-2025-23216
was published
for
github.com/argoproj/argo-cd
(Go)
Jan 30, 2025
Kubewarden-Controller information leak via AdmissionPolicyGroup Resource
Moderate
CVE-2025-24784
was published
for
github.com/kubewarden/kubewarden-controller
(Go)
Jan 30, 2025
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information...
Moderate
Unreviewed
CVE-2024-8494
was published
Jan 30, 2025
kube-audit-rest's example logging configuration could disclose secret values in the audit log
Moderate
CVE-2025-24884
was published
for
github.com/RichardoC/kube-audit-rest
(Go)
Jan 29, 2025
RuoYi allowed unauthorized attackers to view the session ID of the admin in the system monitoring
High
CVE-2024-57436
was published
for
com.ruoyi:ruoyi
(Maven)
Jan 29, 2025
A path
traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix...
High
Unreviewed
CVE-2025-0659
was published
Jan 28, 2025
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
Moderate
CVE-2025-24360
was published
for
@nuxt/vite-builder
(npm)
Jan 27, 2025
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2024-11090
was published
Jan 26, 2025
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is...
High
Unreviewed
CVE-2024-13562
was published
Jan 25, 2025
HL7 FHIR IG Publisher potentially exposes GitHub repo user and credential information
Moderate
CVE-2025-24363
was published
for
org.hl7.fhir.publisher:org.hl7.fhir.publisher.cli
(Maven)
Jan 24, 2025
An issue was identified in Fleet Server where Fleet policies that could contain sensitive...
Critical
Unreviewed
CVE-2024-52975
was published
Jan 23, 2025
An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent...
High
Unreviewed
CVE-2024-43707
was published
Jan 23, 2025
ProTip!
Advisories are also available from the
GraphQL API