GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,692
Erlang
34
GitHub Actions
27
Go
2,279
Maven
5,000+
npm
3,931
NuGet
708
pip
3,699
Pub
12
RubyGems
919
Rust
957
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,862 advisories
Filter by severity
H2O Vulnerable to Denial of Service (DoS) and File Write
High
CVE-2024-10572
was published
for
ai.h2o:h2o-ext-xgboost
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
High
CVE-2024-10550
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Spring Security Does Not Enforce Password Length
High
CVE-2025-22228
was published
for
org.springframework.security:spring-security-crypto
(Maven)
Mar 20, 2025
The WikiManager REST API allows any user to create wikis
High
CVE-2025-29926
was published
for
org.xwiki.platform:xwiki-platform-wiki-rest-default
(Maven)
Mar 19, 2025
XWiki allows unregistered users to access private pages information through REST endpoint
High
CVE-2025-29925
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Mar 19, 2025
XWiki uses the wrong wiki reference in AuthorizationManager
High
CVE-2025-29924
was published
for
org.xwiki.platform:xwiki-platform-security-authorization-api
(Maven)
Mar 19, 2025
Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-30196
was published
for
org.jenkins-ci.plugins:anchorchain
(Maven)
Mar 19, 2025
SmallRye Fault Tolerance out-of-memory (OOM) issue
High
CVE-2025-2240
was published
for
io.smallrye:smallrye-fault-tolerance-core
(Maven)
Mar 12, 2025
com.xwiki.confluencepro:application-confluence-migrator-pro-ui's application homepage is public
High
CVE-2025-27604
was published
for
com.xwiki.confluencepro:application-confluence-migrator-pro-ui
(Maven)
Mar 7, 2025
Emissary May Use a Broken or Risky Cryptographic Algorithm
High
CVE-2025-27508
was published
for
gov.nsa.emissary:emissary
(Maven)
Mar 5, 2025
OpenDJ Denial of Service (DoS) using alias loop
High
CVE-2025-27497
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Mar 5, 2025
Wildfly Elytron integration susceptible to brute force attacks via CLI
High
CVE-2025-23368
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Mar 4, 2025
Pebble has Arbitrary Local File Inclusion (LFI) Vulnerability via `include` macro
High
CVE-2025-1686
was published
for
io.pebbletemplates:pebble
(Maven)
Feb 28, 2025
io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout
High
CVE-2025-1634
was published
for
io.quarkus:quarkus-resteasy
(Maven)
Feb 26, 2025
Instaclustr Cassandra-Lucene-Index allows bypass of Cassandra RBAC
High
CVE-2025-26511
was published
for
com.instaclustr:cassandra-lucene-index-plugin
(Maven)
Feb 13, 2025
Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance
High
CVE-2025-1247
was published
for
io.quarkus:quarkus-rest
(Maven)
Feb 13, 2025
SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
High
CVE-2025-24970
was published
for
io.netty:netty-handler
(Maven)
Feb 10, 2025
SQL injection in JeecgBoot
High
CVE-2024-57606
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Feb 8, 2025
Apache James vulnerable to denial of service through JMAP HTML to text conversion
High
CVE-2024-45626
was published
for
org.apache.james:james-server-jmap-draft
(Maven)
Feb 6, 2025
Apache James vulnerable to denial of service through the use of IMAP literals
High
CVE-2024-37358
was published
for
org.apache.james.protocols:protocols-imap
(Maven)
Feb 6, 2025
Netplex Json-smart Uncontrolled Recursion vulnerability
High
CVE-2024-57699
was published
for
net.minidev:json-smart
(Maven)
Feb 6, 2025
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
High
CVE-2025-23015
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 4, 2025
Snowflake JDBC allows an untrusted search path on Windows
High
CVE-2025-24789
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Jan 29, 2025
RuoYi allowed unauthorized attackers to view the session ID of the admin in the system monitoring
High
CVE-2024-57436
was published
for
com.ruoyi:ruoyi
(Maven)
Jan 29, 2025
Apache Solr vulnerable to Execution with Unnecessary Privileges
High
CVE-2025-24814
was published
for
org.apache.solr:solr-core
(Maven)
Jan 27, 2025
ProTip!
Advisories are also available from the
GraphQL API