GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,811
Erlang
36
GitHub Actions
32
Go
2,396
Maven
5,000+
npm
4,033
NuGet
721
pip
3,824
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
527 advisories
Filter by severity
Para Inserts Sensitive Information into Log File for Facebook authentication
Moderate
CVE-2025-49009
was published
for
com.erudika:para-server
(Maven)
Jun 6, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Moderate
CVE-2025-48493
was published
for
yiisoft/yii2-redis
(Composer)
Jun 5, 2025
Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance...
Moderate
Unreviewed
CVE-2020-14518
was published
May 24, 2022
Para Server Logs Sensitive Information
Moderate
CVE-2025-48955
was published
for
com.erudika:para-server
(Maven)
May 30, 2025
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and...
Moderate
Unreviewed
CVE-2025-31199
was published
May 30, 2025
A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token...
Moderate
Unreviewed
CVE-2022-32217
was published
Sep 25, 2022
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing...
Moderate
Unreviewed
CVE-2022-23716
was published
Sep 29, 2022
Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens
Moderate
CVE-2022-31684
was published
for
io.projectreactor.netty:reactor-netty-http
(Maven)
Oct 20, 2022
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3...
Moderate
Unreviewed
CVE-2022-3018
was published
Oct 28, 2022
Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages...
Moderate
Unreviewed
CVE-2022-43673
was published
Nov 18, 2022
Recording of environment variables, configured for running containers, in Docker Desktop...
Moderate
Unreviewed
CVE-2025-3911
was published
Apr 29, 2025
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
Moderate
Unreviewed
CVE-2025-46432
was published
Apr 25, 2025
Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure...
Moderate
Unreviewed
CVE-2025-2300
was published
Apr 22, 2025
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could...
Moderate
Unreviewed
CVE-2017-5137
was published
May 17, 2022
The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel...
Moderate
Unreviewed
CVE-2017-5549
was published
May 14, 2022
A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The...
Moderate
Unreviewed
CVE-2022-38756
was published
Dec 17, 2022
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup &...
Moderate
Unreviewed
CVE-2025-24651
was published
Apr 17, 2025
Directus inserts access token from query string into logs
Moderate
CVE-2024-47822
was published
for
@directus/api
(npm)
Apr 14, 2025
A privacy issue was addressed with improved private data redaction for log entries. This issue is...
Moderate
Unreviewed
CVE-2023-40425
was published
Oct 25, 2023
Microsoft Identity Web Exposes Client Secrets and Certificate Information in Service Logs
Moderate
CVE-2025-32016
was published
for
Microsoft.Identity.Abstractions
(NuGet)
Apr 9, 2025
ray vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-1979
was published
for
ray
(pip)
Mar 6, 2025
Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive...
Moderate
Unreviewed
CVE-2025-25013
was published
Apr 9, 2025
Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Drupal to...
Moderate
Unreviewed
CVE-2024-31247
was published
Apr 10, 2024
Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects...
Moderate
Unreviewed
CVE-2024-31245
was published
Apr 10, 2024
ProTip!
Advisories are also available from the
GraphQL API