GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,476
Erlang
33
GitHub Actions
24
Go
2,203
Maven
5,000+
npm
3,857
NuGet
696
pip
3,639
Pub
12
RubyGems
912
Rust
913
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,560 advisories
Filter by severity
Elasticsearch allocation of resources without limits or throttling leads to crash
Moderate
CVE-2024-43709
was published
for
org.elasticsearch:elasticsearch
(Maven)
Jan 21, 2025
Solon Path Traversal
Moderate
CVE-2025-1584
was published
for
org.noear:solon-web-staticfiles
(Maven)
Feb 23, 2025
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
Moderate
CVE-2023-20861
was published
for
org.springframework:spring-expression
(Maven)
Mar 23, 2023
Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled
Moderate
CVE-2023-28668
was published
for
org.jenkins-ci.plugins:role-strategy
(Maven)
Apr 2, 2023
Spring Security Missing Authorization vulnerability
Moderate
CVE-2024-38810
was published
for
org.springframework.security:spring-security-core
(Maven)
Aug 20, 2024
WSO2 incorrect authorization vulnerability
Moderate
CVE-2024-2321
was published
for
org.wso2.am:am-parent
(Maven)
Feb 27, 2025
Apache StreamPipes has improper privilege management in a REST interface
Moderate
CVE-2024-24778
was published
for
org.apache.streampipes:streampipes-parent
(Maven)
Mar 3, 2025
Prototype pollution in json-pointer
Moderate
CVE-2020-7709
was published
for
json-pointer
(Maven)
May 10, 2021
Jenkins Open Redirect vulnerability
Moderate
CVE-2025-27625
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 6, 2025
Jenkins cross-site request forgery (CSRF) vulnerability
Moderate
CVE-2025-27624
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 6, 2025
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
Moderate
CVE-2025-27623
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 6, 2025
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
Moderate
CVE-2025-27622
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 6, 2025
Eclipse Jetty URI parsing of invalid authority
Moderate
CVE-2024-6763
was published
for
org.eclipse.jetty:jetty-http
(Maven)
Oct 14, 2024
Eclipse Jetty has a denial of service vulnerability on DosFilter
Moderate
CVE-2024-9823
was published
for
org.eclipse.jetty.ee10:jetty-ee10-servlets
(Maven)
Oct 14, 2024
HTTP/2 Stream Cancellation Attack
Moderate
CVE-2023-44487
was published
for
com.typesafe.akka:akka-http-core
(Go)
Oct 10, 2023
LocalS3 Project Bucket Operations Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-2466-4485-4pxj
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Vulnerable to XML External Entity (XXE) Injection via Bucket Tagging API
Moderate
GHSA-v232-254c-m6p7
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 XML Parser Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-47qw-ccjm-9c2c
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
CVE-2025-0604
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Mar 10, 2025
Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims
Moderate
CVE-2025-1391
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 10, 2025
Duplicate Advisory: Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
GHSA-m3hp-8546-5qmr
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Jan 22, 2025
•
withdrawn
Duplicate Advisory: Keycloak allows Incorrect Assignment of an Organization to a User
Moderate
GHSA-rq4w-cjrr-h8w8
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 17, 2025
•
withdrawn
Apache Wicket: An attacker can intentionally trigger a memory leak
Moderate
CVE-2024-53299
was published
for
org.apache.wicket:wicket-core
(Maven)
Jan 23, 2025
Infinispan vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-0736
was published
for
org.infinispan:infinispan-parent
(Maven)
Jan 28, 2025
Jenkins allows Cross-Site Scripting (XSS) via Crafted URL
Moderate
CVE-2012-4439
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Apr 23, 2022
ProTip!
Advisories are also available from the
GraphQL API