GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,951
Erlang
39
GitHub Actions
38
Go
2,607
Maven
5,000+
npm
4,251
NuGet
757
pip
4,017
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
556 advisories
Filter by severity
Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4...
Moderate
Unreviewed
CVE-2025-62262
was published
Oct 27, 2025
Jberet: jberet-core logging database credentials
Moderate
CVE-2024-1102
was published
for
org.jberet:jberet-core
(Maven)
Apr 25, 2024
Rancher exposes sensitive information through audit logs
Moderate
CVE-2024-58269
was published
for
github.com/rancher/rancher
(Go)
Oct 24, 2025
OpenBao and Vault Leak []byte Fields in Audit Logs
Moderate
CVE-2025-62705
was published
for
github.com/openbao/openbao
(Go)
Oct 22, 2025
OpenBao leaks HTTPRawBody in Audit Logs
Moderate
CVE-2025-62513
was published
for
github.com/openbao/openbao
(Go)
Oct 22, 2025
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker...
Moderate
Unreviewed
CVE-2025-24984
was published
Mar 11, 2025
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged...
Moderate
Unreviewed
CVE-2023-21492
was published
May 4, 2023
A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11...
Moderate
Unreviewed
CVE-2025-46752
was published
Oct 16, 2025
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and...
Moderate
Unreviewed
CVE-2025-20329
was published
Oct 15, 2025
The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2025-10486
was published
Oct 15, 2025
Insertion of sensitive information into log file in Active Directory Federation Services allows...
Moderate
Unreviewed
CVE-2025-59258
was published
Oct 14, 2025
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized...
Moderate
Unreviewed
CVE-2025-59197
was published
Oct 14, 2025
Insertion of sensitive information into log file in Windows StateRepository API allows an...
Moderate
Unreviewed
CVE-2025-59203
was published
Oct 14, 2025
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized...
Moderate
Unreviewed
CVE-2025-47979
was published
Oct 14, 2025
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Moderate
CVE-2025-37727
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 10, 2025
The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
Moderate
Unreviewed
CVE-2025-10645
was published
Oct 7, 2025
A potential security
vulnerability has been identified in the Poly Clariti Manager for versions...
Moderate
Unreviewed
CVE-2025-43485
was published
Jul 23, 2025
Lightbend Alpakka Kafka logs credentials on debug level
Moderate
CVE-2023-29471
was published
for
com.typesafe.akka:akka-stream-kafka_2.11
(Maven)
Apr 27, 2023
An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic...
Moderate
Unreviewed
CVE-2024-37283
was published
Aug 12, 2024
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information...
Moderate
Unreviewed
CVE-2025-9985
was published
Sep 26, 2025
A vulnerability existed in Firefox for Android where potentially sensitive library locations were...
Moderate
Unreviewed
CVE-2025-4090
was published
Apr 29, 2025
A logging issue was addressed with improved data redaction. This issue is fixed in tvOS 26,...
Moderate
Unreviewed
CVE-2025-43354
was published
Sep 16, 2025
A logging issue was addressed with improved data redaction. This issue is fixed in tvOS 26,...
Moderate
Unreviewed
CVE-2025-43303
was published
Sep 16, 2025
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in...
Moderate
Unreviewed
CVE-2025-10221
was published
Sep 10, 2025
secrets-store-sync-controller discloses service account tokens in logs
Moderate
CVE-2025-7445
was published
for
sigs.k8s.io/secrets-store-sync-controller
(Go)
Sep 5, 2025
ProTip!
Advisories are also available from the
GraphQL API