GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
6,036 advisories
Filter by severity
Timing Attack Vulnerability in SCRAM Authentication
Moderate
CVE-2025-59432
was published
for
com.ongres.scram:scram-common
(Maven)
Sep 16, 2025
Liferay Portal has unchecked input for loop condition vulnerability in XML-RPC
Moderate
CVE-2025-43801
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 16, 2025
Spring Expression language property modification using Spring Cloud Gateway Server WebFlux
Critical
CVE-2025-41243
was published
for
org.springframework.cloud:spring-cloud-gateway-server-webflux
(Maven)
Sep 16, 2025
Spring Security annotation detection mechanism has authorization bypass
High
CVE-2025-41248
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 16, 2025
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
Openfire has potential identity spoofing issue via unsafe CN parsing
Moderate
CVE-2025-59154
was published
for
org.igniterealtime.openfire:xmppserver
(Maven)
Sep 16, 2025
Liferay has Insecure Default Initialization of Resource issue
Moderate
CVE-2025-43797
was published
for
com.liferay:com.liferay.site.admin.web
(Maven)
Sep 16, 2025
Liferay Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-43802
was published
for
com.liferay.workspace:com.liferay.ticket.workspace
(Maven)
Sep 16, 2025
Liferay DXP Missing Critical Step in Authentication
Low
CVE-2025-43798
was published
for
com.liferay:com.liferay.multi.factor.authentication.timebased.otp.web
(Maven)
Sep 15, 2025
Liferay Portal Uses Default Password
Moderate
CVE-2025-43799
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 15, 2025
Liferay Portal Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2025-43800
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
(Maven)
Sep 15, 2025
Liferay Portal has External Control of System or Configuration Settings
Low
CVE-2025-43792
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Sep 15, 2025
Liferay Portal vulnerable to Cross-site Scripting
Moderate
CVE-2025-43791
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
(Maven)
Sep 15, 2025
Liferay Portal has Improper Validation of Specified Quantity in Input
Moderate
CVE-2025-43793
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 15, 2025
Apache Fory Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-59328
was published
for
org.apache.fory:fory-core
(Maven)
Sep 15, 2025
Liferay Portal has stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-43794
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 15, 2025
Liferay Portal's System, Instance and Site Settings are vulnerable to Open Redirect
Moderate
CVE-2025-43795
was published
for
com.liferay:com.liferay.configuration.admin.web
(Maven)
Sep 12, 2025
Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack
High
CVE-2025-43796
was published
for
com.liferay:com.liferay.portal.vulcan.api
(Maven)
Sep 12, 2025
Liferay Portal's selection modal is vulnerable to XSS
Moderate
CVE-2025-43787
was published
for
com.liferay:com.liferay.users.admin.web
(Maven)
Sep 12, 2025
Liferay Portal JSON Web Services Direct Class Invocation Enables Service Access Policy Execution
Low
CVE-2025-43789
was published
for
com.liferay:com.liferay.comment.web
(Maven)
Sep 12, 2025
Liferay Portal's Organization Selector exposes organization data to remote authenticated users
Moderate
CVE-2025-43788
was published
for
com.liferay:com.liferay.organizations.item.selector.web
(Maven)
Sep 12, 2025
Liferay Portal API Allows Authenticated Users to Access Workflow Definitions by Name
Moderate
CVE-2025-43782
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl
(Maven)
Sep 11, 2025
Liferay Portal is vulnerable to Insecure Direct Object Reference (IDOR) attack through Authentication Bypass
High
CVE-2025-43790
was published
for
com.liferay:com.liferay.object.service
(Maven)
Sep 11, 2025
Liferay Portal is vulnerable to Reflected XSS attack through get_editor path
Moderate
CVE-2025-43783
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Sep 10, 2025
Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data
Moderate
CVE-2025-43784
was published
for
com.liferay:com.liferay.headless.builder.impl
(Maven)
Sep 10, 2025
ProTip!
Advisories are also available from the
GraphQL API