GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,915 advisories
Filter by severity
io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout
High
CVE-2025-1634
was published
for
io.quarkus:quarkus-resteasy
(Maven)
Feb 26, 2025
Apache Avro Java SDK vulnerable to Improper Input Validation
High
CVE-2023-39410
was published
for
org.apache.avro:avro
(Maven)
Sep 29, 2023
Apache Spark UI can allow impersonation if ACLs enabled
High
CVE-2022-33891
was published
for
org.apache.spark:spark-parent_2.12
(Maven)
Jul 19, 2022
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page
High
CVE-2021-29050
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Feb 21, 2024
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
High
CVE-2025-41235
was published
for
org.springframework.cloud:spring-cloud-gateway-server
(Maven)
May 30, 2025
XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
High
CVE-2025-54385
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jul 25, 2025
Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
High
CVE-2025-50151
was published
for
org.apache.jena:jena
(Maven)
Jul 21, 2025
XXL-JOB vulnerable to Server-Side Request Forgery
High
CVE-2024-24113
was published
for
com.xuxueli:xxl-job
(Maven)
Feb 8, 2024
XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)
High
CVE-2022-43183
was published
for
com.xuxueli:xxl-job-core
(Maven)
Nov 17, 2022
Eclipse GlassFish is vulnerable to Server Side Request Forgery attacks through specific endpoints
High
CVE-2024-9408
was published
for
org.glassfish.main.admingui:console-common
(Maven)
Jul 16, 2025
Apache James vulnerable to denial of service through the use of IMAP literals
High
CVE-2024-37358
was published
for
org.apache.james.protocols:protocols-imap
(Maven)
Feb 6, 2025
RuoYi vulnerable to arbitrary file download
High
CVE-2023-27025
was published
for
com.ruoyi:ruoyi
(Maven)
Apr 2, 2023
Liferay Portal Path Traversal Vulnerability via the Hypermedia REST APIs Module
High
CVE-2022-28981
was published
for
com.liferay:com.liferay.headless.discovery.web
(Maven)
Sep 23, 2022
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
High
CVE-2025-53689
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Jul 14, 2025
Liferay Portal and Liferay DXP fails to properly import users from LDAP
High
CVE-2021-38266
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Mar 4, 2022
Apache Zeppelin exposes server resources to unauthenticated attackers
High
CVE-2024-41169
was published
for
org.apache.zeppelin:zeppelin-interpreter
(Maven)
Jul 12, 2025
Apache Kylin Session Fixation vulnerability
High
CVE-2024-23590
was published
for
org.apache.kylin:kylin
(Maven)
Nov 4, 2024
Apache Helix Front (UI) component contained a hard-coded secret
High
CVE-2024-22281
was published
for
org.apache.helix:helix
(Maven)
Aug 21, 2024
Jenkins Applitools Eyes Plugin vulnerable to XSS through its Build page
High
CVE-2025-53658
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
High
CVE-2025-48976
was published
for
commons-fileupload:commons-fileupload
(Maven)
Jun 16, 2025
Deserialization of Untrusted Data in Log4j 1.x
High
CVE-2022-23302
was published
for
log4j:log4j
(Maven)
Jan 21, 2022
NULL Pointer Dereference in Protocol Buffers
High
CVE-2021-22570
was published
for
Google.Protobuf
(Composer)
Jan 27, 2022
Apache Kafka Connect vulnerable to Deserialization of Untrusted Data
High
CVE-2023-25194
was published
for
org.apache.kafka:connect
(Maven)
Feb 7, 2023
Remote Code Execution (RCE) vulnerability in dropwizard-validation
High
CVE-2020-5245
was published
for
io.dropwizard:dropwizard-validation
(Maven)
Feb 24, 2020
ProTip!
Advisories are also available from the
GraphQL API