GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
621 advisories
Filter by severity
EVE Seals Vault Key With SHA1 PCRs
Moderate
CVE-2023-43635
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE Doesn't Protect Config Partition with Measured Boot
Moderate
CVE-2023-43634
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE's Debug Functions Unlockable Without Triggering Measured Boot
Moderate
CVE-2023-43633
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE: SSH as Root Unlockable Without Triggering Measured Boot
Moderate
CVE-2023-43631
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE Doesn't Measure Config Partition From 2 Fronts
Moderate
CVE-2023-43630
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
n8n's domain allowlist bypass enables credential exfiltration
Moderate
CVE-2026-25631
was published
for
n8n
(npm)
Feb 4, 2026
malcontent OCI image pull credential exfiltration via malicious registry token realm
Moderate
CVE-2026-24845
was published
for
github.com/chainguard-dev/malcontent
(Go)
Jan 29, 2026
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
Moderate
CVE-2026-21852
was published
for
@anthropic-ai/claude-code
(npm)
Jan 21, 2026
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected...
Moderate
Unreviewed
CVE-2026-1223
was published
Jan 20, 2026
MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local...
Moderate
Unreviewed
CVE-2021-47759
was published
Jan 15, 2026
Firmware update files may expose password hashes for system accounts, which could allow a remote...
Moderate
Unreviewed
CVE-2026-22911
was published
Jan 15, 2026
Insufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before...
Moderate
Unreviewed
CVE-2023-32280
was published
Jan 14, 2026
In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be...
Moderate
Unreviewed
CVE-2025-62327
was published
Jan 7, 2026
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM...
Moderate
Unreviewed
CVE-2025-14148
was published
Dec 15, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently...
Moderate
Unreviewed
CVE-2025-64898
was published
Dec 10, 2025
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2...
Moderate
Unreviewed
CVE-2025-63361
was published
Dec 4, 2025
EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability,...
Moderate
Unreviewed
CVE-2025-13163
was published
Nov 17, 2025
EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability,...
Moderate
Unreviewed
CVE-2025-13164
was published
Nov 17, 2025
A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-13187
was published
Nov 15, 2025
A 3rd-party component exposed its password in process arguments, allowing for low-privileged...
Moderate
Unreviewed
CVE-2025-6571
was published
Nov 11, 2025
Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD),...
Moderate
Unreviewed
CVE-2025-42897
was published
Nov 11, 2025
This vulnerability allows an attacker to access parts of the application that are not protected...
Moderate
Unreviewed
CVE-2025-12461
was published
Oct 29, 2025
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could...
Moderate
Unreviewed
CVE-2024-42192
was published
Oct 16, 2025
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike...
Moderate
Unreviewed
CVE-2025-37728
was published
Oct 7, 2025
The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it...
Moderate
Unreviewed
CVE-2025-27231
was published
Oct 3, 2025
ProTip!
Advisories are also available from the
GraphQL API