GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,688
Erlang
34
GitHub Actions
26
Go
2,274
Maven
5,000+
npm
3,930
NuGet
706
pip
3,696
Pub
12
RubyGems
919
Rust
955
Swift
38
Unreviewed advisories
All unreviewed
5,000+
92 advisories
Filter by severity
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information...
High
Unreviewed
CVE-2025-3529
was published
Apr 23, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Hive Support Hive Support...
High
Unreviewed
CVE-2025-32635
was published
Apr 17, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in WPMinds Simple WP Events...
High
Unreviewed
CVE-2025-32594
was published
Apr 17, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream
Low
CVE-2025-31363
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive...
Moderate
Unreviewed
CVE-2025-26335
was published
Apr 11, 2025
AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent...
Moderate
Unreviewed
CVE-2025-27244
was published
Apr 2, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in viralloops Viral Loops WP...
Moderate
Unreviewed
CVE-2025-31842
was published
Apr 1, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Shipmondo Shipmondo – A...
Moderate
Unreviewed
CVE-2025-27001
was published
Mar 28, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in AppExperts AppExperts –...
Moderate
Unreviewed
CVE-2025-30609
was published
Mar 24, 2025
Liferay Portal and Liferay DXP Reveals Data via Forms
Moderate
CVE-2025-2565
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Mar 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in ExtremePACS Extreme XDS allows...
High
Unreviewed
CVE-2024-7872
was published
Mar 6, 2025
Insecure permissions in TSplus Remote Access v17.30 allow attackers to retrieve a list of all...
Critical
Unreviewed
CVE-2025-26318
was published
Mar 4, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows...
Moderate
Unreviewed
CVE-2025-24567
was published
Feb 14, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in GREYS Korea for WooCommerce...
Moderate
Unreviewed
CVE-2025-24639
was published
Feb 3, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in UkrSolution Barcode Generator...
Moderate
Unreviewed
CVE-2025-24597
was published
Jan 31, 2025
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access...
High
Unreviewed
CVE-2025-24858
was published
Jan 26, 2025
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2...
Moderate
Unreviewed
CVE-2023-38013
was published
Jan 25, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Code for Recovery 12 Step...
Moderate
Unreviewed
CVE-2025-24582
was published
Jan 24, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WPDB to Sql allows...
High
Unreviewed
CVE-2025-23774
was published
Jan 22, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WM Options Import...
High
Unreviewed
CVE-2025-23781
was published
Jan 22, 2025
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP...
Moderate
Unreviewed
CVE-2024-45653
was published
Jan 19, 2025
An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7...
Low
Unreviewed
CVE-2024-46665
was published
Jan 14, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows...
Moderate
Unreviewed
CVE-2024-13269
was published
Jan 9, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable...
High
Unreviewed
CVE-2024-13276
was published
Jan 9, 2025
ProTip!
Advisories are also available from the
GraphQL API