GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,411
Erlang
33
GitHub Actions
22
Go
2,146
Maven
5,000+
npm
3,808
NuGet
687
pip
3,481
Pub
12
RubyGems
897
Rust
899
Swift
38
Unreviewed advisories
All unreviewed
5,000+
470 advisories
Filter by severity
kube-audit-rest's example logging configuration could disclose secret values in the audit log
Moderate
CVE-2025-24884
was published
for
github.com/RichardoC/kube-audit-rest
(Go)
Jan 29, 2025
AWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sending
Moderate
CVE-2023-30610
was published
for
aws-sigv4
(Rust)
Apr 26, 2023
When users log in through the webUI or API using local authentication, BIG-IP Next Central...
Moderate
Unreviewed
CVE-2025-23413
was published
Feb 5, 2025
Using API in the 2N OS device, authorized user can enable logging, which discloses valid...
Moderate
Unreviewed
CVE-2024-13416
was published
Feb 6, 2025
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made...
Moderate
Unreviewed
CVE-2024-2302
was published
Apr 9, 2024
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain...
Moderate
Unreviewed
CVE-2023-23591
was published
Apr 12, 2023
A vulnerability has been identified in Opcenter Intelligence (All versions < V2501). Personal...
Moderate
Unreviewed
CVE-2025-26490
was published
Feb 11, 2025
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Moderate
CVE-2024-52067
was published
for
org.apache.nifi:nifi-framework-core
(Maven)
Feb 11, 2025
A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non...
Moderate
Unreviewed
CVE-2022-35202
was published
Feb 11, 2025
secrets-store-csi-driver discloses service account tokens in logs
Moderate
CVE-2023-2878
was published
for
sigs.k8s.io/secrets-store-csi-driver
(Go)
May 26, 2023
azure-file-csi-driver leaks service account tokens in the logs
Moderate
CVE-2024-3744
was published
for
sigs.k8s.io/azurefile-csi-driver
(Go)
May 15, 2024
Apache Solr Operator liveness and readiness probes may leak basic auth credentials
Moderate
CVE-2024-31391
was published
for
github.com/apache/solr-operator
(Go)
Apr 12, 2024
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Moderate
CVE-2023-50740
was published
for
org.apache.linkis:linkis
(Maven)
Mar 6, 2024
MongoDB Driver may publish events containing authentication-related data
Moderate
CVE-2021-32050
was published
for
github.com/mongodb/mongo-swift-driver
(Composer)
Aug 29, 2023
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
Moderate
CVE-2023-44483
was published
for
org.apache.santuario:xmlsec
(Maven)
Oct 20, 2023
Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs
Moderate
CVE-2023-31417
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 26, 2023
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2...
Moderate
Unreviewed
CVE-2025-1075
was published
Feb 19, 2025
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User...
Moderate
Unreviewed
CVE-2024-13818
was published
Feb 21, 2025
A highly privileged account can overwrite arbitrary files on the system with log output. The log...
Moderate
Unreviewed
CVE-2024-28072
was published
May 3, 2024
Kubernetes client-go library logs may disclose credentials to unauthorized users
Moderate
CVE-2019-11250
was published
for
k8s.io/client-go
(Go)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API