GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,670
Maven
5,000+
npm
4,296
NuGet
760
pip
4,075
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
45 advisories
Filter by severity
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the...
Moderate
Unreviewed
CVE-2025-36371
was published
Nov 19, 2025
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP...
Moderate
Unreviewed
CVE-2025-31954
was published
Nov 5, 2025
Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4...
Low
Unreviewed
CVE-2025-32916
was published
Oct 9, 2025
In the HTTP request, the username and password are transferred directly in the URL as parameters....
Moderate
Unreviewed
CVE-2025-58584
was published
Oct 6, 2025
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and...
High
Unreviewed
CVE-2025-56551
was published
Oct 3, 2025
An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a...
Moderate
Unreviewed
CVE-2025-50709
was published
Sep 17, 2025
QuickCMS sends password and login via GET Request. This allows a local attacker with access to...
Moderate
Unreviewed
CVE-2025-54542
was published
Aug 28, 2025
An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager...
Moderate
Unreviewed
CVE-2025-8997
was published
Aug 25, 2025
An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of...
Moderate
Unreviewed
CVE-2025-51651
was published
Jul 14, 2025
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 ...
Moderate
Unreviewed
CVE-2025-40742
was published
Jul 8, 2025
File Browser allows sensitive data to be transferred in URL
Moderate
CVE-2025-52901
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 30, 2025
The application sends user credentials as URL parameters instead of POST bodies, making it...
Moderate
Unreviewed
CVE-2025-49188
was published
Jun 12, 2025
Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework...
Moderate
Unreviewed
CVE-2025-3943
was published
May 22, 2025
: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB...
Moderate
Unreviewed
CVE-2024-9877
was published
Apr 30, 2025
Moodle's mod_data edit/delete pages pass CSRF token in GET parameter
Low
CVE-2025-3637
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to...
Moderate
Unreviewed
CVE-2025-24948
was published
Apr 15, 2025
VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext
Low
CVE-2025-32021
was published
for
weblate
(pip)
Apr 15, 2025
A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic....
Moderate
Unreviewed
CVE-2025-2356
was published
Mar 17, 2025
Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1...
High
Unreviewed
CVE-2021-41719
was published
Mar 4, 2025
A Password Transmitted over Query String vulnerability has been found in Trivision Camera NC227WF...
Moderate
Unreviewed
CVE-2025-1738
was published
Feb 27, 2025
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access...
Moderate
Unreviewed
CVE-2025-26058
was published
Feb 18, 2025
The Mojave Inverter uses the GET method for sensitive information.
High
Unreviewed
CVE-2025-26473
was published
Feb 14, 2025
A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the...
Moderate
Unreviewed
CVE-2024-12012
was published
Feb 13, 2025
A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build...
Moderate
Unreviewed
CVE-2025-0730
was published
Jan 27, 2025
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity...
High
Unreviewed
CVE-2025-22387
was published
Jan 4, 2025
ProTip!
Advisories are also available from the
GraphQL API