GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,692
Erlang
34
GitHub Actions
27
Go
2,279
Maven
5,000+
npm
3,931
NuGet
708
pip
3,699
Pub
12
RubyGems
919
Rust
957
Swift
38
Unreviewed advisories
All unreviewed
5,000+
5,563 advisories
Filter by severity
Narayana deadlock via multiple join requests sent to LRA Coordinator
Moderate
CVE-2024-8447
was published
for
org.jboss.narayana.rts:lra-coordinator-jar
(Maven)
Jan 2, 2025
Apache Tomcat Rewrite rule bypass
Low
CVE-2025-31651
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 28, 2025
Apache Tomcat Denial of Service via invalid HTTP priority header
Moderate
CVE-2025-31650
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 28, 2025
The WikiManager REST API allows any user to create wikis
High
CVE-2025-29926
was published
for
org.xwiki.platform:xwiki-platform-wiki-rest-default
(Maven)
Mar 19, 2025
Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL Parameter
Moderate
CVE-2021-29049
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Fails to Properly Check User Permissions
Moderate
CVE-2021-33334
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page
Moderate
CVE-2021-33328
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Stores User Passwords in Cleartext
Moderate
CVE-2021-33325
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page
Moderate
CVE-2021-29044
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the Redirect's Admin Page
Moderate
CVE-2021-29045
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Asset Module Parameter
Moderate
CVE-2021-29046
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections
High
CVE-2021-29053
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Fails to Check Permissions
Moderate
CVE-2021-29052
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin Page
Moderate
CVE-2021-29039
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2022
Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication Module
Moderate
CVE-2021-29041
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use
High
CVE-2021-29047
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via User Name Parameter
Moderate
CVE-2020-25476
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Vulnerable to Arbitrary Code Execution
High
CVE-2020-13445
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Fails to Sanitize API Data
Moderate
CVE-2020-13444
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Keycloak hostname verification
High
CVE-2025-3501
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 30, 2025
Graylog Allows Session Takeover via Insufficient HTML Sanitization
High
CVE-2025-46827
was published
for
org.graylog2:graylog2-server
(Maven)
May 7, 2025
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
Moderate
CVE-2025-30373
was published
for
org.graylog2:graylog2-server
(Maven)
Apr 7, 2025
Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser
High
GHSA-q9q2-3ppx-mwqf
was published
for
org.graylog2:graylog2-server
(Maven)
May 7, 2025
Deserialization of Untrusted Data in Bouncy castle
Critical
CVE-2018-1000613
was published
for
org.bouncycastle:bcprov-jdk15on
(Maven)
Oct 17, 2018
Spring MVC controller vulnerable to a DoS attack
Moderate
CVE-2024-38828
was published
for
org.springframework:spring-webmvc
(Maven)
Nov 18, 2024
ProTip!
Advisories are also available from the
GraphQL API