GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,478
Erlang
33
GitHub Actions
24
Go
2,208
Maven
5,000+
npm
3,863
NuGet
696
pip
3,640
Pub
12
RubyGems
913
Rust
919
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,562 advisories
Filter by severity
Solon Vulnerable to Path Traversal
Moderate
CVE-2025-2961
was published
for
org.noear:solon-view
(Maven)
Mar 31, 2025
Infinispan Potential Out of Memory Error via REST Compare API Buffer API
Moderate
CVE-2024-6875
was published
for
org.infinispan:infinispan-query
(Maven)
Mar 28, 2025
WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack
Moderate
CVE-2024-12369
was published
for
org.wildfly.security:wildfly-elytron
(Maven)
Mar 25, 2025
Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache
Moderate
CVE-2025-2559
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 25, 2025
Spring Security Vulnerable to Authorization Bypass via Security Annotations
Moderate
CVE-2025-22223
was published
for
org.springframework.security:spring-security-core
(Maven)
Mar 24, 2025
Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2025-30474
was published
for
org.apache.commons:commons-vfs2
(Maven)
Mar 23, 2025
aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
Moderate
CVE-2025-2622
was published
for
com.aizuda:snail-job
(Maven)
Mar 22, 2025
Apache Oozie Cross-Site Scripting (XSS)
Moderate
CVE-2025-26796
was published
for
org.apache.oozie:oozie-core
(Maven)
Mar 22, 2025
Liferay Portal and Liferay DXP Reveals Data via Forms
Moderate
CVE-2025-2565
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Mar 20, 2025
Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
Moderate
CVE-2025-27888
was published
for
org.apache.druid:druid
(Maven)
Mar 20, 2025
H2O Vulnerable to Execution of Arbitrary Files
Moderate
CVE-2024-6863
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2025-2536
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Mar 19, 2025
Wire has Uncontrolled Recursion on Nested Groups
Moderate
CVE-2024-58103
was published
for
com.squareup.wire:wire-runtime
(Maven)
Mar 16, 2025
Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check
Moderate
CVE-2020-36843
was published
for
net.i2p.crypto:eddsa
(Maven)
Mar 13, 2025
Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin
Moderate
CVE-2025-27867
was published
for
org.apache.felix:org.apache.felix.http.webconsoleplugin
(Maven)
Mar 12, 2025
Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record
Moderate
CVE-2025-27017
was published
for
org.apache.nifi:nifi-mongodb-services
(Maven)
Mar 12, 2025
Apache Camel Message Header Injection through request parameters
Moderate
CVE-2025-29891
was published
for
org.apache.camel:camel-support
(Maven)
Mar 12, 2025
Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims
Moderate
CVE-2025-1391
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 10, 2025
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
CVE-2025-0604
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Mar 10, 2025
LocalS3 XML Parser Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-47qw-ccjm-9c2c
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Vulnerable to XML External Entity (XXE) Injection via Bucket Tagging API
Moderate
GHSA-v232-254c-m6p7
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Bucket Operations Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-2466-4485-4pxj
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 CreateBucketConfiguration Endpoint XML External Entity (XXE) Injection
Moderate
CVE-2025-27136
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
Moderate
CVE-2025-27636
was published
for
org.apache.camel:camel-support
(Maven)
Mar 9, 2025
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
Moderate
CVE-2025-27623
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 6, 2025
ProTip!
Advisories are also available from the
GraphQL API