GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,035
Maven
5,000+
npm
3,732
NuGet
662
pip
3,413
Pub
12
RubyGems
891
Rust
865
Swift
36
Unreviewed advisories
All unreviewed
5,000+
54 advisories
Filter by severity
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
High
CVE-2022-30618
was published
for
@strapi/strapi
(npm)
May 20, 2022
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
High
CVE-2022-30617
was published
for
@strapi/strapi
(npm)
May 20, 2022
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault
Moderate
CVE-2021-38554
was published
for
github.com/hashicorp/vault
(Go)
Aug 30, 2021
Vulnerability of residual files not being deleted after an update in the ChinaDRM module....
High
Unreviewed
CVE-2021-46813
was published
Jun 14, 2022
Exposure of sensitive system information due to uncleared debug information in firmware for some...
Moderate
Unreviewed
CVE-2021-33080
was published
May 13, 2022
Sensitive information in resource not removed before reuse in firmware for some Intel(R) SSD and...
Moderate
Unreviewed
CVE-2021-33082
was published
May 13, 2022
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without...
Low
Unreviewed
CVE-2020-11740
was published
May 24, 2022
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3...
Moderate
Unreviewed
CVE-2019-20637
was published
May 24, 2022
Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for...
Low
Unreviewed
CVE-2020-13179
was published
May 24, 2022
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors...
Moderate
Unreviewed
CVE-2020-8696
was published
May 24, 2022
Some websites have a feature "Show Password" where clicking a button will change a password field...
Moderate
Unreviewed
CVE-2020-26965
was published
May 24, 2022
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information...
High
Unreviewed
CVE-2021-0340
was published
May 24, 2022
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to...
High
Unreviewed
CVE-2021-31780
was published
May 24, 2022
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP...
High
Unreviewed
CVE-2020-14301
was published
May 24, 2022
Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000...
Moderate
Unreviewed
CVE-2021-3031
was published
May 24, 2022
Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit Oak
High
CVE-2020-1940
was published
for
org.apache.jackrabbit:oak-core
(Maven)
Dec 10, 2021
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable...
Moderate
Unreviewed
CVE-2018-1062
was published
May 13, 2022
Wasmtime may have data leakage between instances in the pooling allocator
High
CVE-2022-39393
was published
for
wasmtime
(Rust)
Nov 10, 2022
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS)....
High
Unreviewed
CVE-2020-36476
was published
May 24, 2022
A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks...
Moderate
Unreviewed
CVE-2023-1637
was published
Mar 28, 2023
usememos/memos may leak user information to an authenticated user
Moderate
CVE-2022-4734
was published
for
github.com/usememos/memos
(Go)
Dec 27, 2022
Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects
Moderate
CVE-2022-0536
was published
for
follow-redirects
(npm)
Feb 10, 2022
Cockpit Content Platform vulnerable to 2FA bypass
High
CVE-2022-2818
was published
for
cockpit-hq/cockpit
(Composer)
Aug 16, 2022
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository polonel/trudesk...
Moderate
Unreviewed
CVE-2022-1893
was published
Jun 1, 2022
Failure to strip the Cookie header on change in host or HTTP downgrade
High
CVE-2022-31042
was published
for
guzzlehttp/guzzle
(Composer)
Jun 9, 2022
ProTip!
Advisories are also available from the
GraphQL API