GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,677
Erlang
34
GitHub Actions
26
Go
2,265
Maven
5,000+
npm
3,918
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,618 advisories
Filter by severity
Cross site scripting in Apache JSPWiki
Moderate
CVE-2024-27136
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jun 24, 2024
H2O Vulnerable to Execution of Arbitrary Files
Moderate
CVE-2024-6863
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Apache Submarine Commons Utils has a hard-coded secret
Moderate
CVE-2024-36264
was published
for
apache-submarine
(Maven)
Jun 12, 2024
Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
Moderate
CVE-2024-34447
was published
for
org.bouncycastle:bcprov-jdk12
(Maven)
May 3, 2024
Liferay Portal and Liferay DXP Reveals Data via Forms
Moderate
CVE-2025-2565
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Mar 20, 2025
Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin
Moderate
CVE-2025-27867
was published
for
org.apache.felix:org.apache.felix.http.webconsoleplugin
(Maven)
Mar 12, 2025
FitNesse Cross-site Scripting vulnerability
Moderate
CVE-2024-28128
was published
for
org.fitnesse:fitnesse
(Maven)
Mar 18, 2024
Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
Moderate
CVE-2025-27888
was published
for
org.apache.druid:druid
(Maven)
Mar 20, 2025
Apache Oozie Cross-Site Scripting (XSS)
Moderate
CVE-2025-26796
was published
for
org.apache.oozie:oozie-core
(Maven)
Mar 22, 2025
aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
Moderate
CVE-2025-2622
was published
for
com.aizuda:snail-job
(Maven)
Mar 22, 2025
Spring Security Vulnerable to Authorization Bypass via Security Annotations
Moderate
CVE-2025-22223
was published
for
org.springframework.security:spring-security-core
(Maven)
Mar 24, 2025
Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2025-30474
was published
for
org.apache.commons:commons-vfs2
(Maven)
Mar 23, 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
Moderate
CVE-2025-27636
was published
for
org.apache.camel:camel-support
(Maven)
Mar 9, 2025
WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack
Moderate
CVE-2024-12369
was published
for
org.wildfly.security:wildfly-elytron
(Maven)
Mar 25, 2025
Jenkins MQ Notifier Plugin exposes sensitive information in build logs
Moderate
CVE-2024-28154
was published
for
com.sonymobile.jenkins.plugins.mq:mq-notifier
(Maven)
Mar 6, 2024
Narayana deadlock via multiple join requests sent to LRA Coordinator
Moderate
CVE-2024-8447
was published
for
org.jboss.narayana.rts:lra-coordinator-jar
(Maven)
Jan 2, 2025
Privilege escalation in Liferay Portal
Moderate
CVE-2022-45320
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Feb 20, 2024
Infinispan Potential Out of Memory Error via REST Compare API Buffer API
Moderate
CVE-2024-6875
was published
for
org.infinispan:infinispan-query
(Maven)
Mar 28, 2025
Solon Vulnerable to Path Traversal
Moderate
CVE-2025-2961
was published
for
org.noear:solon-view
(Maven)
Mar 31, 2025
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
Moderate
CVE-2024-8184
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Oct 14, 2024
Netty QUIC hash collision DoS attack
Moderate
CVE-2025-29908
was published
for
io.netty.incubator:netty-incubator-codec-quic
(Maven)
Mar 31, 2025
Apache Camel Missing Header Out Filter Leads to Potential Bypass/Injection Vulnerability
Moderate
CVE-2025-30177
was published
for
org.apache.camel:camel-undertow
(Maven)
Apr 1, 2025
Jenkins Missing Permission Check
Moderate
CVE-2025-31720
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Apr 2, 2025
Exposure of system-scoped Kubernetes credentials in Jenkins Kubernetes Credentials Provider Plugin
Moderate
CVE-2023-24425
was published
for
com.cloudbees.jenkins.plugins:kubernetes-credentials-provider
(Maven)
Jan 26, 2023
Jenkins Missing Permission Check
Moderate
CVE-2025-31721
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Apr 2, 2025
ProTip!
Advisories are also available from the
GraphQL API