GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,436
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,694
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at...
Low
Unreviewed
CVE-2026-1694
was published
Feb 26, 2026
Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option...
Low
Unreviewed
CVE-2025-49300
was published
Dec 16, 2025
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could...
Low
Unreviewed
CVE-2025-52639
was published
Nov 18, 2025
O2 UK through 2025-05-17 allows subscribers to determine the Cell ID of other subscribers by...
Low
Unreviewed
CVE-2025-48219
was published
May 18, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream
Low
CVE-2025-31363
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7...
Low
Unreviewed
CVE-2024-46665
was published
Jan 14, 2025
Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
Low
CVE-2024-50378
was published
for
apache-airflow
(pip)
Nov 8, 2024
Undici vulnerable to data leak when using response.arrayBuffer()
Low
CVE-2024-38372
was published
for
undici
(npm)
Jul 9, 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16...
Low
Unreviewed
CVE-2023-5831
was published
Nov 6, 2023
Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel
Low
CVE-2023-3299
was published
for
github.com/hashicorp/nomad
(Go)
Jul 20, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to...
Low
Unreviewed
CVE-2023-2620
was published
Jul 13, 2023
Some Dahua software products have a vulnerability of sensitive information leakage. After...
Low
Unreviewed
CVE-2022-45428
was published
Dec 27, 2022
Potential sensitive information disclosed in error reports
Low
CVE-2021-21416
was published
for
django-registration
(pip)
Apr 6, 2021
ProTip!
Advisories are also available from the
GraphQL API