GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,330
Erlang
31
GitHub Actions
21
Go
2,091
Maven
5,000+
npm
3,756
NuGet
678
pip
3,443
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
50 advisories
Filter by severity
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an attacker can use a specially...
Low
Unreviewed
CVE-2023-32712
was published
Jun 1, 2023
SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an...
Moderate
Unreviewed
CVE-2023-31405
was published
Jul 11, 2023
While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603,...
Moderate
Unreviewed
CVE-2023-36924
was published
Jul 11, 2023
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to...
High
Unreviewed
CVE-2023-36925
was published
Jul 11, 2023
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in...
Moderate
Unreviewed
CVE-2023-4065
was published
Sep 27, 2023
Sentry vulnerable to leaking superuser cleartext password in logs
High
CVE-2024-32474
was published
for
sentry
(pip)
Apr 18, 2024
Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs...
Moderate
Unreviewed
CVE-2023-39461
was published
May 3, 2024
flask-cors vulnerable to log injection when the log level is set to debug
Moderate
CVE-2024-1681
was published
for
flask-cors
(pip)
Apr 19, 2024
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can...
Critical
Unreviewed
CVE-2024-0095
was published
Jun 14, 2024
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection...
High
Unreviewed
CVE-2024-25047
was published
May 2, 2024
Keycloak vulnerable to log Injection during WebAuthn authentication or registration
Moderate
CVE-2023-6484
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 17, 2024
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly...
Moderate
Unreviewed
CVE-2024-31845
was published
May 21, 2024
Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint...
Low
Unreviewed
CVE-2024-23194
was published
Jul 11, 2024
Improper Output Neutralization for Logs in Spring Framework
Moderate
CVE-2021-22096
was published
for
org.springframework:spring
(Maven)
May 24, 2022
A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f....
Moderate
Unreviewed
CVE-2024-8334
was published
Aug 30, 2024
A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been...
Moderate
Unreviewed
CVE-2024-8297
was published
Aug 29, 2024
Insertion of Sensitive Information into Log File and Improper Output Neutralization for Logs in ansible
Moderate
CVE-2020-14332
was published
for
ansible
(pip)
Feb 9, 2022
Improper Output Neutralization and Improper Encoding or Escaping of Output for Logs in ansible
Moderate
CVE-2020-14330
was published
for
ansible
(pip)
Feb 9, 2022
Ansible Uses Plugins That Disclose Credentials
High
CVE-2019-14846
was published
for
ansible
(pip)
May 24, 2022
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The...
Critical
Unreviewed
CVE-2023-46322
was published
Oct 23, 2023
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs....
Critical
Unreviewed
CVE-2023-46321
was published
Oct 23, 2023
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible...
Moderate
Unreviewed
CVE-2024-7696
was published
Jan 7, 2025
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3
could allow an authenticated user...
Moderate
Unreviewed
CVE-2024-52891
was published
Jan 7, 2025
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in...
Moderate
Unreviewed
CVE-2023-28952
was published
May 3, 2024
Ansible-core information disclosure flaw
Moderate
CVE-2024-0690
was published
for
ansible-core
(pip)
Feb 6, 2024
ProTip!
Advisories are also available from the
GraphQL API