GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,954
Maven
5,000+
npm
4,606
NuGet
787
pip
4,305
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
208 advisories
Filter by severity
Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive...
High
Unreviewed
CVE-2025-36573
was published
Jun 12, 2025
** DISPUTED ** An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode...
High
Unreviewed
CVE-2018-18466
was published
May 13, 2022
Contrast workload secrets leak to logs on INFO level
High
GHSA-h5f8-crrq-4pw8
was published
for
github.com/edgelesssys/contrast
(Go)
May 28, 2025
AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine...
High
Unreviewed
CVE-2024-6451
was published
Aug 19, 2024
In affected versions of Octopus Server it is possible for target discovery to print certain...
High
Unreviewed
CVE-2022-2721
was published
Nov 25, 2022
MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8...
High
Unreviewed
CVE-2015-8977
was published
May 17, 2022
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI...
High
Unreviewed
CVE-2016-9882
was published
May 13, 2022
canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output
High
CVE-2025-31479
was published
for
canonical/get-workflow-version-action
(GitHub Actions)
Apr 2, 2025
GitHub PAT written to debug artifacts
High
CVE-2025-24362
was published
for
github/codeql-action
(GitHub Actions)
Jan 24, 2025
An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker...
High
Unreviewed
CVE-2024-24272
was published
Mar 22, 2024
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and...
High
Unreviewed
CVE-2025-20231
was published
Mar 27, 2025
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an...
High
Unreviewed
CVE-2023-22362
was published
Feb 13, 2023
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
High
CVE-2023-46215
was published
for
apache-airflow
(pip)
Oct 28, 2023
An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs...
High
Unreviewed
CVE-2023-46672
was published
Nov 15, 2023
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch...
High
Unreviewed
CVE-2024-29959
was published
Apr 19, 2024
When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode,...
High
Unreviewed
CVE-2024-29957
was published
Apr 19, 2024
A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the...
High
Unreviewed
CVE-2024-29958
was published
Apr 19, 2024
Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle allows...
High
Unreviewed
CVE-2025-24556
was published
Feb 3, 2025
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3,...
High
Unreviewed
CVE-2025-23374
was published
Jan 30, 2025
Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm...
High
Unreviewed
CVE-2024-42407
was published
Dec 12, 2024
Git credentials are exposed in Atlantis logs
High
CVE-2024-52009
was published
for
github.com/runatlantis/atlantis
(Go)
Nov 8, 2024
AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes...
High
Unreviewed
CVE-2024-52940
was published
Nov 18, 2024
APM Server vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2024-23448
was published
for
github.com/elastic/apm-server
(Go)
Feb 8, 2024
An Innsertion of Sensitive Information into Log File vulnerability in SUSE SUSE Manager Server...
High
Unreviewed
CVE-2023-22644
was published
Sep 20, 2023
Insertion of Sensitive Information into Log File in ansible
High
CVE-2021-20178
was published
for
ansible
(pip)
Jun 1, 2021
ProTip!
Advisories are also available from the
GraphQL API