GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
9,939 advisories
Filter by severity
Omni vulnerable to information leak via API
High
CVE-2025-61688
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
The External Login plugin for WordPress is vulnerable to sensitive information exposure in all...
Moderate
Unreviewed
CVE-2025-11196
was published
Oct 15, 2025
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an...
Low
Unreviewed
CVE-2025-59294
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual...
Moderate
Unreviewed
CVE-2025-59260
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized...
Low
Unreviewed
CVE-2025-59284
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized...
Moderate
Unreviewed
CVE-2025-59186
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows High Availability Services...
Moderate
Unreviewed
CVE-2025-59184
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an...
Moderate
Unreviewed
CVE-2025-58739
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an...
Moderate
Unreviewed
CVE-2025-59188
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core...
Moderate
Unreviewed
CVE-2025-59211
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized...
Moderate
Unreviewed
CVE-2025-55699
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter...
Moderate
Unreviewed
CVE-2025-55336
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core...
Moderate
Unreviewed
CVE-2025-59209
was published
Oct 14, 2025
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet...
Moderate
Unreviewed
CVE-2025-59921
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized...
Moderate
Unreviewed
CVE-2025-55683
was published
Oct 14, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ariva Computer Accord...
Critical
Unreviewed
CVE-2024-1744
was published
Sep 6, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PORTY Smart Tech...
High
Unreviewed
CVE-2024-1662
was published
Jun 5, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Yordam Information...
High
Unreviewed
CVE-2024-6406
was published
Sep 18, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Utarit Information...
High
Unreviewed
CVE-2024-3305
was published
Sep 12, 2024
The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers...
High
Unreviewed
CVE-2014-2374
was published
May 17, 2022
Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for...
Moderate
Unreviewed
CVE-2014-0786
was published
May 17, 2022
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows...
Moderate
Unreviewed
CVE-2014-2377
was published
May 17, 2022
Rack has a Possible Information Disclosure Vulnerability
Moderate
CVE-2025-61780
was published
for
rack
(RubyGems)
Oct 10, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not...
Moderate
Unreviewed
CVE-2025-49177
was published
Jun 17, 2025
ProTip!
Advisories are also available from the
GraphQL API