GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,746
Maven
5,000+
npm
4,346
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
6,163 advisories
Filter by severity
Duplicate Advisory: Keycloak hostname verification
High
GHSA-r934-w73g-v4p8
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 29, 2025
•
withdrawn
org.ini4j allows attackers to cause a Denial of Service (DoS)
High
CVE-2022-41404
was published
for
org.ini4j:ini4j
(Maven)
Oct 12, 2022
GeoTools has XML External Entity (XXE) Processing Vulnerability in XSD schema handling
Critical
GHSA-826p-4gcg-35vw
was published
for
org.geotools:gt-wfs-ng
(Maven)
Jun 9, 2025
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
High
CVE-2024-12397
was published
for
io.quarkus.http:quarkus-http-core
(Maven)
Dec 12, 2024
OpenRefine vulnerable to zip slip in project import
Moderate
CVE-2023-37476
was published
for
org.openrefine:main
(Maven)
Jul 18, 2023
GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
High
CVE-2024-29198
was published
for
org.geoserver.web:gs-app
(Maven)
Jun 10, 2025
GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
Critical
CVE-2024-34711
was published
for
org.geoserver.main:gs-main
(Maven)
Jun 10, 2025
GWC Home Page communicate version and revision information
Moderate
CVE-2024-38524
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
Coverage REST API Server Side Request Forgery
Moderate
CVE-2024-40625
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
GeoServer Missing Authorization on REST API Index
Moderate
CVE-2025-27505
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
GeoServer Infinite Loop Vulnerability in Jiffle process
High
CVE-2025-30145
was published
for
org.geoserver.extension:gs-wps-core
(Maven)
Jun 10, 2025
Apache InLong Deserialization of Untrusted Data Vulnerability
High
CVE-2025-27531
was published
for
org.apache.inlong:inlong-manager
(Maven)
Jun 6, 2025
[XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service
High
CVE-2025-30220
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint
High
GHSA-2p76-gc46-5fvc
was published
for
org.geonetwork-opensource:gn-web-app
(Maven)
Jun 10, 2025
GeoServer vulnerable to SSRF in TestWfsPost for specific targets, e.g. PHP + Nginx
High
GHSA-68cf-j696-wvv9
was published
for
org.geoserver:gs-wfs
(Maven)
Jun 10, 2025
Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service Page
Moderate
CVE-2024-45478
was published
for
org.apache.ranger:ranger
(Maven)
Jan 22, 2025
Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
Moderate
CVE-2025-27817
was published
for
org.apache.kafka:kafka-clients
(Maven)
Jun 10, 2025
pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
High
CVE-2025-49146
was published
for
org.postgresql:postgresql
(Maven)
Jun 11, 2025
Undertow Uncontrolled Resource Consumption
High
CVE-2021-3629
was published
for
io.undertow:undertow-core
(Maven)
May 25, 2022
XWiki allows SQL injection in query endpoint of REST API with Oracle
Critical
CVE-2024-56158
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 12, 2025
Para Inserts Sensitive Information into Log File for Facebook authentication
Moderate
CVE-2025-49009
was published
for
com.erudika:para-server
(Maven)
Jun 6, 2025
XWiki allows privilege escalation through link refactoring
High
CVE-2025-49580
was published
for
org.xwiki.platform:xwiki-platform-refactoring-default
(Maven)
Jun 13, 2025
XWiki allows remote code execution through default value of wiki macro wiki-type parameters
High
CVE-2025-49581
was published
for
org.xwiki.platform:xwiki-platform-rendering-wikimacro-store
(Maven)
Jun 13, 2025
XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
Moderate
CVE-2025-49583
was published
for
org.xwiki.platform:xwiki-platform-notifications-notifiers-default
(Maven)
Jun 13, 2025
XWiki makes title of inaccessible pages available through the class property values REST API
High
CVE-2025-49584
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Jun 13, 2025
ProTip!
Advisories are also available from the
GraphQL API