GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,950 advisories
Filter by severity
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Moderate
CVE-2025-43764
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
(Maven)
Aug 23, 2025
Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect
Moderate
CVE-2025-43767
was published
for
com.liferay:com.liferay.info.impl
(Maven)
Aug 23, 2025
Liferay Portal JSONWS API endpoint shares sensitive information
Moderate
CVE-2025-43768
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Aug 23, 2025
Liferay Portal vulnerable to Stored XSS in Components portlet
Moderate
CVE-2025-43769
was published
for
com.liferay:com.liferay.plugins.admin.web
(Maven)
Aug 23, 2025
Liferay Portal vulnerable to Reflected XSS with the referer and forward parameter
Moderate
CVE-2025-43770
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Aug 23, 2025
Liferay Portal users are able to add system admin portlets to pages
Moderate
CVE-2025-43759
was published
for
com.liferay:com.liferay.layout.impl
(Maven)
Aug 22, 2025
Liferay Portal's unauthenticated users can access loaded files via URL before submitting the object entry
Moderate
CVE-2025-43758
was published
for
com.liferay:com.liferay.frontend.js.web
(Maven)
Aug 22, 2025
Liferay Portal users can upload an unlimited amount of files
Moderate
CVE-2025-43762
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
(Maven)
Aug 22, 2025
Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint
Moderate
CVE-2025-43761
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Aug 22, 2025
Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect
Moderate
CVE-2025-43760
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 22, 2025
Liferay Portal User Enumeration Vulnerability via the Create Account Page
Moderate
CVE-2025-43751
was published
for
com.liferay:com.liferay.login.web
(Maven)
Aug 22, 2025
JeecgBoot SQL Injection Vulnerability
Moderate
CVE-2025-51825
was published
for
org.jeecgframework.boot:jeecg-boot-base-core
(Maven)
Aug 22, 2025
Bouncy Castle for Java has Uncontrolled Resource Consumption Vulnerability
Moderate
CVE-2025-9341
was published
for
org.bouncycastle:bc-fips
(Maven)
Aug 22, 2025
Liferay Portal's Unlimited File Upload Could Result in DoS
Moderate
CVE-2025-43752
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 22, 2025
Liferay Portal Username Enumeration Vulnerability
Moderate
CVE-2025-43754
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 21, 2025
Liferay Portal Stored Cross-Site Scripting Vulnerability via GroupPagesPortlet_type Parameter
Moderate
CVE-2025-43755
was published
for
com.liferay:com.liferay.layout.admin.web
(Maven)
Aug 21, 2025
Liferay Portal Reflected Cross-Site Scripting Vulnerability via snippet Parameter
Moderate
CVE-2025-43756
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 21, 2025
Duplicate Advisory: Keycloak Potential Variable Reference in Model Storage Services
Moderate
GHSA-w2wj-hw98-233h
was published
for
org.keycloak:keycloak-model-storage-services
(Maven)
Aug 21, 2025
•
withdrawn
Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition Parameter
Moderate
CVE-2025-43757
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Liferay Portal Vulnerable to Cross-Site Scripting in Dynamic Data Mapping
Moderate
CVE-2025-43746
was published
for
ccom.liferay:com.liferay.dynamic.data.mapping.web
(Maven)
Aug 20, 2025
Liferay Portal Unvalidated File Upload
Moderate
CVE-2025-43750
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.web
(Maven)
Aug 20, 2025
Liferay Portal Unauthenticated File Access via URL
Moderate
CVE-2025-43749
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Liferay Portal Vulnerable to Cross-Site Scripting through URLs
Moderate
CVE-2025-43742
was published
for
com.liferay:com.liferay.layout.type.controller.display.page
(Maven)
Aug 20, 2025
Liferay Portal Vulnerable to Cross-Site Scripting via assetTagNames Parameter
Moderate
CVE-2025-43741
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.java
Moderate
CVE-2024-39954
was published
for
org.apache.eventmesh:eventmesh-runtime
(Maven)
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API