GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,792
Erlang
36
GitHub Actions
29
Go
2,377
Maven
5,000+
npm
4,002
NuGet
720
pip
3,802
Pub
12
RubyGems
927
Rust
984
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
50 advisories
Filter by severity
In ConnectWise PSA versions older than 2025.9, a
vulnerability exists where authenticated users...
Moderate
Unreviewed
CVE-2025-7204
was published
Jul 9, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize...
Moderate
Unreviewed
CVE-2025-53322
was published
Jun 27, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Stripe...
Moderate
Unreviewed
CVE-2025-53309
was published
Jun 27, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic...
Moderate
Unreviewed
CVE-2025-49294
was published
Jun 6, 2025
The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all...
Moderate
Unreviewed
CVE-2025-5733
was published
Jun 6, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social...
Moderate
Unreviewed
CVE-2025-39498
was published
May 26, 2025
Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive...
Moderate
Unreviewed
CVE-2025-26335
was published
Apr 11, 2025
AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent...
Moderate
Unreviewed
CVE-2025-27244
was published
Apr 2, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in viralloops Viral Loops WP...
Moderate
Unreviewed
CVE-2025-31842
was published
Apr 1, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Shipmondo Shipmondo – A...
Moderate
Unreviewed
CVE-2025-27001
was published
Mar 28, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in AppExperts AppExperts –...
Moderate
Unreviewed
CVE-2025-30609
was published
Mar 24, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows...
Moderate
Unreviewed
CVE-2025-24567
was published
Feb 14, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in GREYS Korea for WooCommerce...
Moderate
Unreviewed
CVE-2025-24639
was published
Feb 3, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in UkrSolution Barcode Generator...
Moderate
Unreviewed
CVE-2025-24597
was published
Jan 31, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows...
Moderate
Unreviewed
CVE-2024-13269
was published
Jan 9, 2025
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2...
Moderate
Unreviewed
CVE-2023-38013
was published
Jan 25, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Code for Recovery 12 Step...
Moderate
Unreviewed
CVE-2025-24582
was published
Jan 24, 2025
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP...
Moderate
Unreviewed
CVE-2024-45653
was published
Jan 19, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows...
Moderate
Unreviewed
CVE-2025-22303
was published
Jan 7, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation...
Moderate
Unreviewed
CVE-2024-8429
was published
Dec 17, 2024
Insertion of Sensitive Information Into Sent Data vulnerability in wpdebuglog PostBox allows...
Moderate
Unreviewed
CVE-2024-54309
was published
Dec 13, 2024
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba...
Moderate
Unreviewed
CVE-2023-34968
was published
Jul 20, 2023
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco...
Moderate
Unreviewed
CVE-2021-1425
was published
Nov 18, 2024
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 ...
Moderate
Unreviewed
CVE-2024-6747
was published
Oct 10, 2024
The goTenna Pro broadcast key name is always sent unencrypted and could reveal the location of...
Moderate
Unreviewed
CVE-2024-47128
was published
Sep 26, 2024
ProTip!
Advisories are also available from the
GraphQL API