GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,039
Maven
5,000+
npm
4,779
NuGet
824
pip
4,380
Pub
12
RubyGems
987
Rust
1,143
Swift
50
Unreviewed advisories
All unreviewed
5,000+
113 advisories
Filter by severity
Apache Struts vulnerable to possible DoS attack when using URLValidator
Moderate
CVE-2016-4465
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Improper Input Validation in OpenSymphony XWork
Moderate
CVE-2008-6504
was published
for
com.opensymphony:xwork
(Maven)
May 17, 2022
Apache Axis2 has Improper Input Validation
Moderate
CVE-2012-5785
was published
for
org.apache.axis2:axis2
(Maven)
May 17, 2022
Improper Input Validation in Apache POI
Moderate
CVE-2014-3574
was published
for
org.apache.poi:poi
(Maven)
May 17, 2022
Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
Moderate
CVE-2011-1475
was published
for
org.apache.tomcat:tomcat
(Maven)
May 17, 2022
Improper Input Validation in Apache Batik
Moderate
CVE-2015-0250
was published
for
org.apache.xmlgraphics:batik
(Maven)
May 17, 2022
Denial of service in Apache Tomcat
Moderate
CVE-2014-0095
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 17, 2022
JBoss RichFaces Improper Input Validation vulnerability
Moderate
CVE-2014-0086
was published
for
org.richfaces:richfaces
(Maven)
May 17, 2022
Jenkins has CRLF Injection Vulnerability in the CLI
Moderate
CVE-2016-0789
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Improper Input Validation in Apache Tomcat
Moderate
CVE-2011-4858
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
MitM on Jenkins Maven Plugin
Moderate
CVE-2017-1000397
was published
for
org.jenkins-ci.main:maven-plugin
(Maven)
May 14, 2022
Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks
Moderate
CVE-2017-1000402
was published
for
org.jenkins-ci.plugins:swarm-client
(Maven)
May 14, 2022
Apache Struts vulnerable to possible DoS attack when using URLValidator
Moderate
CVE-2016-8738
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
Arbitrary file write vulnerability in Jenkins Fortify CloudScan Plugin
Moderate
CVE-2018-1000607
was published
for
org.jenkins-ci.plugins:fortify-cloudscan-jenkins-plugin
(Maven)
May 14, 2022
Improper Input Validation in Apache Jackrabbit
Moderate
CVE-2015-1833
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
May 14, 2022
Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandler
Moderate
CVE-2010-1587
was published
for
org.apache.activemq:activemq-web-console
(Maven)
May 14, 2022
Improper Input Validation in Bouncy Castle
Moderate
CVE-2013-1624
was published
for
org.bouncycastle:bcprov-jdk15on
(Maven)
May 14, 2022
Jenkins allows HTTP Injection and Response Splitting
Moderate
CVE-2012-6072
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Improper Input Validation in Apache Karaf
Moderate
CVE-2014-0219
was published
for
org.apache.karaf:apache-karaf
(Maven)
May 14, 2022
Improper Input Validation in Jetty
Moderate
CVE-2011-4461
was published
for
org.eclipse.jetty:jetty-server
(Maven)
May 14, 2022
Improper Input Validation in Apache Tomcat
Moderate
CVE-2011-2526
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions
Moderate
CVE-2012-3544
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Apache Tomcat is vulnerable to HTTP request-smuggling
Moderate
CVE-2013-4286
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Input Validation in Apache Tomcat
Moderate
CVE-2014-0033
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Input Validation in Apache Tomcat
Moderate
CVE-2014-0227
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API