GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
6,316 advisories
Filter by severity
Denial of service via deserialization attack in nifi
Moderate
CVE-2017-15703
was published
for
org.apache.nifi:nifi-framework-cluster-protocol
(Maven)
Oct 25, 2019
Insufficiently Protected Credentials in Pivotal Reactor Netty
High
CVE-2019-11284
was published
for
io.projectreactor.netty:reactor-netty
(Maven)
Oct 23, 2019
io.ratpack:ratpack-core vulnerable to Improper Neutralization of Special Elements in Output ('Injection')
High
CVE-2019-17513
was published
for
io.ratpack:ratpack-core
(Maven)
Oct 21, 2019
Out-of-Memory Error in Bouncy Castle Crypto
High
CVE-2019-17359
was published
for
org.bouncycastle:bcprov-jdk14
(Maven)
Oct 17, 2019
Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
Critical
CVE-2019-17195
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Oct 16, 2019
Cross-site scripting in Swagger-UI
Critical
CVE-2019-17495
was published
for
io.springfox:springfox-swagger-ui
(Maven)
Oct 15, 2019
Cross-site scripting in Apache JSPWiki
Moderate
CVE-2019-12404
was published
for
org.apache.jspwiki:jspwiki-war
(Maven)
Oct 11, 2019
Cross-site scripting in Apache JSPWiki
Moderate
CVE-2019-10089
was published
for
org.apache.jspwiki:jspwiki-war
(Maven)
Oct 11, 2019
Cross-site scripting in Apache JSPWiki
Moderate
CVE-2019-10087
was published
for
org.apache.jspwiki:jspwiki-war
(Maven)
Oct 11, 2019
Cross-site scripting in Apache JSPWiki
Moderate
CVE-2019-10090
was published
for
org.apache.jspwiki:jspwiki-war
(Maven)
Oct 11, 2019
HTTP Request Smuggling in Netty
High
CVE-2019-16869
was published
for
io.netty:netty-all
(Maven)
Oct 11, 2019
Denial of Service in Apache Commons Compress
High
CVE-2019-12402
was published
for
io.github.1tchy.java9modular.org.apache.commons:commons-compress
(Maven)
Oct 11, 2019
Timing attack on HMAC signature comparison in Apache Tapestry
Critical
CVE-2019-10071
was published
for
org.apache.tapestry:tapestry-core
(Maven)
Sep 26, 2019
Polymorphic Typing issue in FasterXML jackson-databind
Critical
CVE-2019-16335
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 23, 2019
Polymorphic Typing issue in FasterXML jackson-databind
Critical
CVE-2019-14540
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 23, 2019
Cross-site scripting in Sakai
Moderate
CVE-2019-16148
was published
for
org.sakaiproject:chat-base
(Maven)
Sep 23, 2019
Improper Input Validation and Cross-Site Request Forgery in Keycloak
High
CVE-2019-10199
was published
for
org.keycloak:keycloak-core
(Maven)
Sep 23, 2019
Improper Verification of Cryptographic Signature in keycloak
Moderate
CVE-2019-10201
was published
for
org.keycloak:keycloak-core
(Maven)
Sep 23, 2019
Improper Handling of Exceptional Conditions and Origin Validation Error in Eclipse Paho Java client library
Moderate
CVE-2019-11777
was published
for
org.eclipse.paho:org.eclipse.paho.client.mqttv3
(Maven)
Sep 17, 2019
Incorrect Resource Transfer Between Spheres in eclipse-wtp
Moderate
CVE-2019-10753
was published
for
com.diffplug.spotless:spotless-eclipse-cdt
(Maven)
Sep 11, 2019
OS Command Injection in Nexus Yum Repository Plugin
High
CVE-2019-5475
was published
for
org.sonatype.nexus.plugins:nexus-yum-repository-plugin
(Maven)
Sep 11, 2019
Improper input validation in Apache Santuario XML Security for Java
Moderate
CVE-2019-12400
was published
for
org.apache.santuario:xmlsec
(Maven)
Aug 27, 2019
Cross-site Scripting in Jooby
Moderate
CVE-2019-15477
was published
for
org.jooby:jooby
(Maven)
Aug 27, 2019
Cross-site Scripting in Ignite Realtime Openfire
Moderate
CVE-2019-15488
was published
for
org.igniterealtime.openfire:xmppserver
(Maven)
Aug 27, 2019
Cross-site scripting in Apache Ranger
Moderate
CVE-2019-12397
was published
for
org.apache.ranger:ranger
(Maven)
Aug 16, 2019
ProTip!
Advisories are also available from the
GraphQL API