GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,749
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
47 advisories
Filter by severity
Para Inserts Sensitive Information into Log File for Facebook authentication
Moderate
CVE-2025-49009
was published
for
com.erudika:para-server
(Maven)
Jun 6, 2025
Para Server Logs Sensitive Information
Moderate
CVE-2025-48955
was published
for
com.erudika:para-server
(Maven)
May 30, 2025
Apache ActiveMQ Artemis Vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-27391
was published
for
org.apache.activemq:artemis-project
(Maven)
Apr 9, 2025
Apache Pulsar Kafka Connector Logs Sensitive Information in Application Logs
Moderate
CVE-2025-30677
was published
for
org.apache.pulsar:pulsar-io-kafka
(Maven)
Apr 9, 2025
Snowflake JDBC Driver client-side encryption key in DEBUG logs
Low
CVE-2025-27496
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Mar 13, 2025
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Moderate
CVE-2024-52067
was published
for
org.apache.nifi:nifi-framework-core
(Maven)
Feb 11, 2025
Infinispan vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-0736
was published
for
org.infinispan:infinispan-parent
(Maven)
Jan 28, 2025
Quarkus CXF logs passwords and other secrets
Moderate
CVE-2024-9621
was published
for
io.quarkiverse.cxf:quarkus-cxf
(Maven)
Oct 8, 2024
Elasticsearch Insertion of Sensitive Information into Log File
Moderate
CVE-2023-49921
was published
for
org.elasticsearch:elasticsearch
(Maven)
Jul 26, 2024
Bitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin
Moderate
CVE-2024-39460
was published
for
org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source
(Maven)
Jun 26, 2024
SonarQube logs sensitive information
Moderate
CVE-2024-38460
was published
for
org.sonarsource.sonarqube:sonar-web
(Maven)
Jun 16, 2024
Jberet: jberet-core logging database credentials
Moderate
CVE-2024-1102
was published
for
org.jberet:jberet-core
(Maven)
Apr 25, 2024
Jenkins MQ Notifier Plugin exposes sensitive information in build logs
Moderate
CVE-2024-28154
was published
for
com.sonymobile.jenkins.plugins.mq:mq-notifier
(Maven)
Mar 6, 2024
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Moderate
CVE-2023-50740
was published
for
org.apache.linkis:linkis
(Maven)
Mar 6, 2024
Insertion of Sensitive Information into Log File in OWASP DependencyCheck
Moderate
CVE-2024-23686
was published
for
org.owasp:dependency-check-ant
(Maven)
Jan 20, 2024
nvdApiKey is logged in debug mode
Low
GHSA-qqhq-8r2c-c3f5
was published
for
org.owasp:dependency-check-ant
(Maven)
Dec 15, 2023
Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs
Moderate
CVE-2023-31417
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 26, 2023
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
Moderate
CVE-2023-44483
was published
for
org.apache.santuario:xmlsec
(Maven)
Oct 20, 2023
Improper masking of credentials in Jenkins Pipeline Maven Integration Plugin
Moderate
CVE-2023-41934
was published
for
org.jenkins-ci.plugins:pipeline-maven
(Maven)
Sep 6, 2023
Jenkins Folders Plugin information disclosure vulnerability
Moderate
CVE-2023-40338
was published
for
org.jenkins-ci.plugins:cloudbees-folder
(Maven)
Aug 16, 2023
Jenkins HashiCorp Vault Plugin has improper masking of credentials
Moderate
CVE-2023-33001
was published
for
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
(Maven)
May 16, 2023
Lightbend Alpakka Kafka logs credentials on debug level
Moderate
CVE-2023-29471
was published
for
com.typesafe.akka:akka-stream-kafka
(Maven)
Apr 27, 2023
Veracode Scan Jenkins Plugin vulnerable to information disclosure
Moderate
CVE-2023-25721
was published
for
com.veracode.jenkins:veracode-scan
(Maven)
Mar 28, 2023
Spring Vault vulnerable to insertion of sensitive information into a log file
Moderate
CVE-2023-20859
was published
for
org.springframework.vault:spring-vault-core
(Maven)
Mar 23, 2023
OpenNMS has potential Insertion of Sensitive Information into Log File vulnerability
Moderate
CVE-2023-0815
was published
for
org.opennms:opennms
(Maven)
Feb 23, 2023
ProTip!
Advisories are also available from the
GraphQL API