GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,669
Erlang
34
GitHub Actions
26
Go
2,261
Maven
5,000+
npm
3,910
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
5,512 advisories
Filter by severity
Apache Camel Message Header Injection through request parameters
Moderate
CVE-2025-29891
was published
for
org.apache.camel:camel-support
(Maven)
Mar 12, 2025
XWiki uses the wrong wiki reference in AuthorizationManager
High
CVE-2025-29924
was published
for
org.xwiki.platform:xwiki-platform-security-authorization-api
(Maven)
Mar 19, 2025
XWiki allows unregistered users to access private pages information through REST endpoint
High
CVE-2025-29925
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Mar 19, 2025
The WikiManager REST API allows any user to create wikis
High
CVE-2025-29926
was published
for
org.xwiki.platform:xwiki-platform-wiki-rest-default
(Maven)
Mar 19, 2025
Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-30196
was published
for
org.jenkins-ci.plugins:anchorchain
(Maven)
Mar 19, 2025
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2025-2536
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Mar 19, 2025
Apache Seata Vulnerable to Deserialization of Untrusted Data
Low
CVE-2024-47552
was published
for
org.apache.seata:seata-config-core
(Maven)
Mar 20, 2025
Apache Spark UI can allow impersonation if ACLs enabled
High
CVE-2022-33891
was published
for
org.apache.spark:spark-parent_2.12
(Maven)
Jul 19, 2022
Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
High
CVE-2023-50780
was published
for
org.apache.activemq:artemis-cli
(Maven)
Oct 14, 2024
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
High
CVE-2024-12397
was published
for
io.quarkus.http:quarkus-http-core
(Maven)
Dec 12, 2024
H2O Vulnerable to Denial of Service (DoS) and File Write
High
CVE-2024-10572
was published
for
ai.h2o:h2o-ext-xgboost
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
High
CVE-2024-10550
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Undertow Uncontrolled Resource Consumption Vulnerability
High
CVE-2024-1635
was published
for
io.undertow:undertow-core
(Maven)
Feb 20, 2024
H2O Deserialization of Untrusted Data Vulnerability
Critical
CVE-2024-10553
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Cache confusion in Jenkins Eiffel Broadcaster Plugin
Moderate
CVE-2025-24400
was published
for
com.axis.jenkins.plugins.eiffel:eiffel-broadcaster
(Maven)
Jan 22, 2025
Cross site scripting in Apache JSPWiki
Moderate
CVE-2024-27136
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jun 24, 2024
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
High
CVE-2024-10549
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Execution of Arbitrary Files
Moderate
CVE-2024-6863
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Arbitrary File Overwrite via File Export
High
CVE-2024-6854
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
High
CVE-2024-7765
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
High
CVE-2024-7768
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
High
CVE-2024-8062
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Arbitrary File Overwrite
High
CVE-2024-8616
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Apache Submarine Commons Utils has a hard-coded secret
Moderate
CVE-2024-36264
was published
for
apache-submarine
(Maven)
Jun 12, 2024
Apache Seata Vulnerable to Data Amplification
Low
CVE-2024-54016
was published
for
org.apache.seata:seata-parent
(Maven)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API