GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,752
Maven
5,000+
npm
4,357
NuGet
765
pip
4,121
Pub
12
RubyGems
961
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
316 advisories
Filter by severity
Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands
High
CVE-2025-66623
was published
for
io.strimzi:strimzi
(Maven)
Dec 5, 2025
NutzBoot vulnerable to information disclosure
Low
CVE-2025-13804
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
Apache DolphinScheduler sensitive information disclosure
High
CVE-2023-48796
was published
for
apache-dolphinscheduler
(Maven)
Nov 24, 2023
Jenkins Git client Plugin file system information disclosure vulnerability
Moderate
CVE-2025-58458
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Sep 3, 2025
TemporaryFolder on unix-like systems does not limit access to created files
Moderate
CVE-2022-41946
was published
for
org.postgresql:postgresql
(Maven)
Nov 23, 2022
Jberet: jberet-core logging database credentials
Moderate
CVE-2024-1102
was published
for
org.jberet:jberet-core
(Maven)
Apr 25, 2024
ZK Framework vulnerable to malicious POST
High
CVE-2022-36537
was published
for
org.zkoss.zk:zk
(Maven)
Aug 27, 2022
Jenkins discloses project names via fingerprints
High
CVE-2015-5317
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Hazelcast vulnerable to unmasked password exposure
Moderate
CVE-2023-33264
was published
for
com.hazelcast:hazelcast
(Maven)
May 22, 2023
Graylog concurrent PDF report rendering can leak other users' reports
High
CVE-2024-52506
was published
for
org.graylog:graylog-parent
(Maven)
Nov 18, 2024
Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15
Moderate
CVE-2015-7940
was published
for
org.bouncycastle:bcprov-jdk14
(Maven)
Oct 17, 2018
Valtimo scripting engine can be used to gain access to sensitive data or resources
Critical
CVE-2025-58059
was published
for
com.ritense.valtimo:core
(Maven)
Aug 28, 2025
Opencast still publishes global system account credentials
Moderate
CVE-2025-54380
was published
for
org.opencastproject:opencast-common
(Maven)
Jul 25, 2025
OpenSearch unauthorized data access on fields protected by field level security if field is a member of an object
Moderate
GHSA-2rjv-cv85-xhgm
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Aug 1, 2025
OpenSearch unauthorized data access on fields protected by field masking for fields of type ip, geo_point, geo_shape, xy_point, xy_shape
Moderate
GHSA-rrmm-wq7q-h4v5
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Aug 1, 2025
Reactor Netty HTTP is vulnerable to credential leaks during chained redirects
Moderate
CVE-2025-22227
was published
for
io.projectreactor.netty:reactor-netty-http
(Maven)
Jul 16, 2025
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
Moderate
CVE-2022-42132
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Moderate
CVE-2025-26795
was published
for
org.apache.iotdb:iotdb-jdbc
(Maven)
May 14, 2025
Generation of Error Message Containing Sensitive Information in Elasticsearch
Moderate
CVE-2021-22145
was published
for
org.elasticsearch.client:elasticsearch-rest-client
(Maven)
May 24, 2022
Apache IoTDB Discloses Sensitive Information via Log Files
Moderate
CVE-2025-26864
was published
for
apache-iotdb
(Maven)
May 14, 2025
Janssen Config API returns results without scope verification
High
CVE-2025-53003
was published
for
io.jans:jans-config-api-server
(Maven)
Jun 30, 2025
Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling
Moderate
CVE-2024-23944
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 15, 2024
GWC Home Page communicate version and revision information
Moderate
CVE-2024-38524
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
Critical
CVE-2024-34711
was published
for
org.geoserver.main:gs-main
(Maven)
Jun 10, 2025
Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password
Moderate
CVE-2021-29043
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API