GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
6,036 advisories
Filter by severity
Path traversal in Hadoop
Critical
CVE-2022-26612
was published
for
org.apache.hadoop:hadoop-common
(Maven)
Apr 8, 2022
Liferay Portal vulnerable to cross-site scripting in the web content template
Moderate
CVE-2025-43812
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
Moderate
CVE-2025-43813
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameter
Moderate
CVE-2025-43817
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
Moderate
CVE-2025-43818
was published
for
com.liferay:com.liferay.calendar.web
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
Moderate
CVE-2025-43820
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to reflected cross-site scripting on the page configuration page
Moderate
CVE-2025-43815
was published
for
com.liferay:com.liferay.product.navigation.control.menu.web
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the related asset selector
Moderate
CVE-2025-43811
was published
for
com.liferay:com.liferay.item.selector.web
(Maven)
Sep 30, 2025
Lift Sensitive Information Disclosure
Moderate
CVE-2013-3300
was published
for
net.liftweb:lift-webkit
(Maven)
May 17, 2022
Uncontrolled Resource Consumption in Spray JSON
Moderate
CVE-2018-18855
was published
for
io.spray:spray-json_2.10
(Maven)
Jun 28, 2022
Lightbend Alpakka Kafka logs credentials on debug level
Moderate
CVE-2023-29471
was published
for
com.typesafe.akka:akka-stream-kafka_2.11
(Maven)
Apr 27, 2023
Uncontrolled Recursion in Akka HTTP
High
CVE-2021-42697
was published
for
com.typesafe.akka:aakka-http-core_2.13.0-M3
(Maven)
May 24, 2022
fs2-io skips mTLS client verification
Critical
CVE-2022-31183
was published
for
co.fs2:fs2-io
(Maven)
Jul 29, 2022
APM Java Agent Local Privilege Escalation issue
High
CVE-2021-37942
was published
for
co.elastic.apm:apm-agent-parent
(Maven)
Nov 22, 2023
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
High
CVE-2025-55163
was published
for
io.grpc:grpc-netty-shaded
(Maven)
Aug 13, 2025
MinIO Java Client XML Tag Value Substitution Vulnerability
High
CVE-2025-59952
was published
for
io.minio:minio
(Maven)
Sep 29, 2025
WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-4760
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api
(Maven)
Sep 23, 2025
WSO2 Identity Server Apps allows content spoofing in logs
Moderate
CVE-2024-6429
was published
for
org.wso2.identity.apps:authentication-portal
(Maven)
Sep 23, 2025
Liferay Portal and DXP does not properly expire sessions
Moderate
CVE-2025-43819
was published
for
com.liferay:com.liferay.saml.impl
(Maven)
Sep 24, 2025
Code injection in Apache Ant
High
CVE-2020-11979
was published
for
org.apache.ant:ant
(Maven)
Feb 3, 2021
Apache IoTDB: Deserialization of untrusted Data
Critical
CVE-2025-48459
was published
for
org.apache.iotdb:iotdb-confignode
(Maven)
Sep 24, 2025
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Moderate
CVE-2025-58457
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Sep 24, 2025
Jenkins has a log message injection vulnerability
Moderate
CVE-2025-59476
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 17, 2025
XWiki Platform: Remote code execution as guest via DatabaseSearch
Critical
CVE-2024-31982
was published
for
org.xwiki.platform:xwiki-platform-search-ui
(Maven)
Apr 10, 2024
Undertow vulnerable to Race Condition
High
CVE-2024-7885
was published
for
io.undertow:undertow-core
(Maven)
Aug 21, 2024
ProTip!
Advisories are also available from the
GraphQL API