GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,293
Erlang
31
GitHub Actions
21
Go
2,061
Maven
5,000+
npm
3,744
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
752 advisories
Filter by severity
go-retryablehttp can leak basic auth credentials to log files
Moderate
CVE-2024-6104
was published
for
github.com/hashicorp/go-retryablehttp
(Go)
Jun 24, 2024
Bitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin
Moderate
CVE-2024-39460
was published
for
org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source
(Maven)
Jun 26, 2024
IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive...
Moderate
Unreviewed
CVE-2023-30430
was published
Jun 27, 2024
Under certain circumstances unnecessary user details are provided within system logs
Moderate
Unreviewed
CVE-2024-32757
was published
Jul 2, 2024
Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected...
Moderate
Unreviewed
CVE-2024-27154
was published
Jun 14, 2024
The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A...
Moderate
Unreviewed
CVE-2024-27157
was published
Jun 14, 2024
The session cookies, used for authentication, are stored in clear-text logs. An attacker can...
Moderate
Unreviewed
CVE-2024-27156
was published
Jun 14, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A...
High
Unreviewed
CVE-2022-32254
was published
Jun 15, 2022
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can...
Moderate
Unreviewed
CVE-2024-40598
was published
Jul 7, 2024
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special...
Moderate
Unreviewed
CVE-2024-40596
was published
Jul 7, 2024
Multiple Exposure of sensitive information to an unauthorized actor vulnerabilities [CWE-200] in...
High
Unreviewed
CVE-2024-27784
was published
Jul 9, 2024
Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin...
Moderate
Unreviewed
CVE-2024-37270
was published
Jul 10, 2024
Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This...
Moderate
Unreviewed
CVE-2024-37205
was published
Jul 10, 2024
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build...
Moderate
Unreviewed
CVE-2024-41824
was published
Jul 22, 2024
Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13,...
Moderate
Unreviewed
CVE-2022-48319
was published
Feb 20, 2023
An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS...
Moderate
Unreviewed
CVE-2024-39532
was published
Jul 11, 2024
A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive...
Moderate
Unreviewed
CVE-2024-6977
was published
Jul 31, 2024
ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command
Moderate
CVE-2024-41129
was published
for
ops
(pip)
Jul 22, 2024
Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files
Moderate
CVE-2024-41178
was published
for
object_store
(Rust)
Jul 23, 2024
IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive...
Moderate
Unreviewed
CVE-2024-38321
was published
Aug 3, 2024
Elasticsearch Insertion of Sensitive Information into Log File
Moderate
CVE-2023-49921
was published
for
org.elasticsearch:elasticsearch
(Maven)
Jul 26, 2024
Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error
Low
CVE-2024-40636
was published
for
Steeltoe.Discovery.ClientAutofac
(NuGet)
Jul 17, 2024
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b...
Moderate
Unreviewed
CVE-2024-29954
was published
Jun 26, 2024
CubeFS leaks users key in logs
Moderate
CVE-2023-46742
was published
for
github.com/cubefs/cubefs
(Go)
Jan 3, 2024
Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C...
High
Unreviewed
CVE-2024-0912
was published
Jun 6, 2024
ProTip!
Advisories are also available from the
GraphQL API