GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
799 advisories
Filter by severity
ff4j is vulnerable to Remote Code Execution (RCE)
Critical
CVE-2022-44262
was published
for
org.ff4j:ff4j-core
(Maven)
Dec 1, 2022
Jeecg-boot vulnerable to SQL Injection
Critical
CVE-2022-45206
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via updateNullByEmptyString
Critical
CVE-2022-45207
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Command injection in Apache DolphinScheduler Alert Plugins
Critical
CVE-2022-45462
was published
for
org.apache.dolphinscheduler:dolphinscheduler-alert-plugins
(Maven)
Nov 23, 2022
Code injection in quarkus dev ui config editor
Critical
CVE-2022-4116
was published
for
io.quarkus:quarkus-vertx-http-deployment
(Maven)
Nov 22, 2022
Missing Authorization in Filter Stream Converter Application of XWiki-platform
Critical
CVE-2022-41937
was published
for
org.xwiki.platform:xwiki-platform-filter-ui
(Maven)
Nov 21, 2022
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-menu-ui
Critical
CVE-2022-41934
was published
for
org.xwiki.platform:xwiki-platform-menu-ui
(Maven)
Nov 21, 2022
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in xwiki-platform-icon-ui
Critical
CVE-2022-41931
was published
for
org.xwiki.platform:xwiki-platform-icon-ui
(Maven)
Nov 21, 2022
Missing Authorization to enable or disable users in org.xwiki.platform:xwiki-platform-user-profile-ui
Critical
CVE-2022-41930
was published
for
org.xwiki.platform:xwiki-platform-user-profile-ui
(Maven)
Nov 21, 2022
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml
Critical
CVE-2022-41928
was published
for
org.xwiki.platform:xwiki-platform-attachment-ui
(Maven)
Nov 21, 2022
XML External Entity Reference in Jenkins CCCC Plugin
Critical
CVE-2022-45395
was published
for
com.thalesgroup.jenkins-ci.plugins:cccc
(Maven)
Nov 16, 2022
Unsafe deserialization in Apache MINA SSHD
Critical
CVE-2022-45047
was published
for
org.apache.sshd:sshd-common
(Maven)
Nov 16, 2022
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via Friendly URL Module
Critical
CVE-2022-42122
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Fragment Module
Critical
CVE-2022-42120
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Apache SOAP contains unauthenticated RPCRouterServlet
Critical
CVE-2022-45378
was published
for
soap:soap
(Maven)
Nov 14, 2022
Apache Jena vulnerable to Deserialization of Untrusted Data
Critical
CVE-2022-45136
was published
for
org.apache.jena:jena-sdb
(Maven)
Nov 14, 2022
Apache Commons BCEL vulnerable to out-of-bounds write
Critical
CVE-2022-42920
was published
for
org.apache.bcel:bcel
(Maven)
Nov 7, 2022
Apache Ivy does not verify target path when extracting the archive
Critical
CVE-2022-37865
was published
for
org.apache.ivy:ivy
(Maven)
Nov 7, 2022
XWiki OIDC Authenticator vulnerable to bypassing OpenID login by providing a custom provider
Critical
CVE-2022-39387
was published
for
org.xwiki.contrib.oidc:oidc-authenticator
(Maven)
Nov 4, 2022
Spring Security authorization rules can be bypassed via forward or include dispatcher types
Critical
CVE-2022-31692
was published
for
org.springframework.security:spring-security-core
(Maven)
Nov 1, 2022
Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
Critical
CVE-2022-42468
was published
for
org.apache.flume.flume-ng-sources:flume-jms-source
(Maven)
Oct 26, 2022
Heron allows CRLF log injection
Critical
CVE-2021-42010
was published
for
org.apache.heron:heron-api
(Maven)
Oct 24, 2022
Jenkins Script Security Plugin sandbox bypass vulnerability
Critical
CVE-2022-43403
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Oct 19, 2022
Jenkins Pipeline: Groovy Plugin allows sandbox protection bypass and arbitrary code execution
Critical
CVE-2022-43402
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
Oct 19, 2022
Hessian Lite for Apache Dubbo deserialization vulnerability
Critical
CVE-2022-39198
was published
for
com.alibaba:hessian-lite
(Maven)
Oct 19, 2022
ProTip!
Advisories are also available from the
GraphQL API