GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,946 advisories
Filter by severity
Liferay Portal Vulnerable to Denial of Service in Kaleo Forms Admin
High
CVE-2025-43772
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.forms.web
(Maven)
Sep 4, 2025
XStream can be used for Remote Code Execution
High
CVE-2020-26217
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Nov 16, 2020
Unrestricted Upload of File with Dangerous Type Apache Tomcat
High
CVE-2017-12617
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 14, 2022
Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat
High
CVE-2016-8745
was published
for
org.apache.tomcat:tomcat-util
(Maven)
May 14, 2022
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
High
CVE-2023-26464
was published
for
log4j:log4j
(Maven)
Mar 10, 2023
In Bouncy Castle JCE Provider ECDSA does not fully validate ASN.1 encoding of signature on verification
High
CVE-2016-1000342
was published
for
org.bouncycastle:bcprov-jdk14
(Maven)
Oct 17, 2018
Protobuf Java vulnerable to Uncontrolled Resource Consumption
High
CVE-2022-3510
was published
for
com.google.protobuf:protobuf-java
(Maven)
Dec 12, 2022
Protobuf Java vulnerable to Uncontrolled Resource Consumption
High
CVE-2022-3509
was published
for
com.google.protobuf:protobuf-java
(Maven)
Dec 12, 2022
Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers
High
CVE-2021-22570
was published
for
Google.Protobuf
(Composer)
Jan 27, 2022
•
withdrawn
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)
High
CVE-2025-26467
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Aug 25, 2025
Java: DoS Vulnerability in JSON-JAVA
High
CVE-2023-5072
was published
for
org.json:json
(Maven)
Nov 14, 2023
Apache Tomcat Improper Resource Shutdown or Release vulnerability
High
CVE-2025-48989
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 13, 2025
hippo4j Includes Hard Coded Secret Key in JWT Creation
High
CVE-2025-51606
was published
for
cn.hippo4j:hippo4j-core
(Maven)
Aug 21, 2025
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
High
CVE-2025-5115
was published
for
org.eclipse.jetty.http2:http2-common
(Maven)
Aug 20, 2025
Liferay Portal Vulnerable to Cross-Site Request Forgery
High
CVE-2025-43748
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Liferay Portal and Liferay DXP Vulnerable to CSRF via the Layout Module
High
CVE-2023-35030
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Jun 15, 2023
Apache Tomcat - DoS in multipart upload
High
CVE-2025-48988
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jun 16, 2025
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
High
CVE-2024-50379
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Dec 17, 2024
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2024-38286
was published
for
org.apache.tomcat:tomcat-util
(Maven)
Nov 7, 2024
Apache Tomcat - Denial of Service
High
CVE-2024-34750
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jul 3, 2024
Apache Tomcat Improper Input Validation vulnerability
High
CVE-2023-46589
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Nov 28, 2023
Apache Seata: Deserialization of untrusted Data in Apache Seata Server
High
CVE-2025-53606
was published
for
org.apache.seata:seata-serializer-fury
(Maven)
Aug 8, 2025
ProTip!
Advisories are also available from the
GraphQL API