GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,471
Erlang
33
GitHub Actions
24
Go
2,181
Maven
5,000+
npm
3,837
NuGet
696
pip
3,576
Pub
12
RubyGems
911
Rust
910
Swift
38
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope...
High
Unreviewed
CVE-2024-8550
was published
Feb 10, 2025
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with...
High
Unreviewed
CVE-2025-22222
was published
Jan 30, 2025
SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform...
High
Unreviewed
CVE-2025-0061
was published
Jan 14, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
High
Unreviewed
CVE-2024-54279
was published
Dec 16, 2024
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
High
Unreviewed
CVE-2024-50528
was published
Nov 4, 2024
: Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
High
Unreviewed
CVE-2024-48024
was published
Oct 17, 2024
A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM...
High
Unreviewed
CVE-2024-39675
was published
Jul 9, 2024
IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive...
High
Unreviewed
CVE-2024-31887
was published
Apr 17, 2024
Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft...
High
Unreviewed
CVE-2024-22125
was published
Jan 9, 2024
Landscape's server-status page exposed sensitive system information. This data leak included GET...
High
Unreviewed
CVE-2023-32550
was published
Jun 6, 2023
Exposure of Sensitive System Information to an Unauthorized Control Sphere in GitHub repository...
High
Unreviewed
CVE-2022-4366
was published
Dec 8, 2022
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were...
High
Unreviewed
CVE-2022-1902
was published
Sep 2, 2022
ProTip!
Advisories are also available from the
GraphQL API