GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,932 advisories
Filter by severity
Spring-Kafka has Java Deserialization vulnerability When Improperly Configured
High
CVE-2023-34040
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Aug 24, 2023
XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action
High
CVE-2023-40572
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Aug 23, 2023
Apache XML Graphics Batik Server-Side Request Forgery vulnerability
High
CVE-2022-44729
was published
for
org.apache.xmlgraphics:batik-bridge
(Maven)
Aug 22, 2023
Nacos Spring vulnerable to Unsafe Deserialization
High
CVE-2023-39106
was published
for
com.alibaba.nacos:nacos-spring-context
(Maven)
Aug 21, 2023
Apache Ivy External Entity Reference vulnerability
High
CVE-2022-46751
was published
for
org.apache.ivy:ivy
(Maven)
Aug 21, 2023
OpenNMS vulnerable to remote code execution
High
CVE-2023-40313
was published
for
org.opennms:opennms-base-assembly
(Maven)
Aug 17, 2023
PowerJob incorrect access control vulnerability
High
CVE-2023-36106
was published
for
tech.powerjob:powerjob
(Maven)
Aug 17, 2023
Jenkins Docker Swarm Plugin stored cross-site scripting vulnerability
High
CVE-2023-40350
was published
for
org.jenkins-ci.plugins:docker-swarm
(Maven)
Aug 16, 2023
Jenkins Flaky Test Handler Plugin stored cross-site scripting vulnerability
High
CVE-2023-40342
was published
for
org.jenkins-ci.plugins:flaky-test-handler
(Maven)
Aug 16, 2023
Jenkins Shortcut Job Plugin stored cross-site scripting vulnerability
High
CVE-2023-40346
was published
for
io.jenkins.plugins:shortcut-job
(Maven)
Aug 16, 2023
Jenkins Folders Plugin cross-site request forgery vulnerability
High
CVE-2023-40336
was published
for
org.jenkins-ci.plugins:cloudbees-folder
(Maven)
Aug 16, 2023
OpenNMS privilege elevation vulnerability
High
CVE-2023-0872
was published
for
org.opennms:opennms-webapp-rest
(Maven)
Aug 14, 2023
OpenNMS Horizon XXE Injection Vulnerability
High
CVE-2023-0871
was published
for
org.opennms.core:org.opennms.core.xml
(Maven)
Aug 11, 2023
xuxueli xxl-job Cross-Site Request Forgery Vulnerability
High
CVE-2020-24922
was published
for
com.xuxueli:xxl-job
(Maven)
Aug 11, 2023
Denial of service in jackson-dataformats-text
High
CVE-2023-3894
was published
for
com.fasterxml.jackson.dataformat:jackson-dataformats-text
(Maven)
Aug 8, 2023
Cross-site Scripting (XSS) in CrafterCMS
High
CVE-2023-4136
was published
for
org.craftercms:crafter-engine
(Maven)
Aug 3, 2023
Apache NiFi Code Injection vulnerability
High
CVE-2023-36542
was published
for
org.apache.nifi:nifi-cdc-mysql-bundle
(Maven)
Jul 29, 2023
Missing authorization in Jenkins Plug-in for ServiceNow
High
CVE-2023-3442
was published
for
io.jenkins.plugins:servicenow-devops
(Maven)
Jul 26, 2023
Jenkins Stored Cross-site Scripting vulnerability
High
CVE-2023-39151
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jul 26, 2023
Paths contain matrix variables bypass decorators
High
CVE-2023-38493
was published
for
com.linecorp.armeria:armeria
(Maven)
Jul 25, 2023
Arbitrary File Creation in AbstractUnArchiver
High
CVE-2023-37460
was published
for
org.codehaus.plexus:plexus-archiver
(Maven)
Jul 25, 2023
JDBC URL bypassing by allowLoadLocalInfileInPath param
High
CVE-2023-34434
was published
for
org.apache.inlong:manager-pojo
(Maven)
Jul 25, 2023
Hazelcast Executor Services don't check client permissions properly
High
CVE-2023-33265
was published
for
com.hazelcast:hazelcast
(Maven)
Jul 19, 2023
Apache ShardingSphere-Agent Deserialization of Untrusted Data vulnerability
High
CVE-2023-28754
was published
for
org.apache.shardingsphere:shardingsphere
(Maven)
Jul 19, 2023
Spring Security's authorization rules can be misconfigured when using multiple servlets
High
CVE-2023-34035
was published
for
org.springframework.security:spring-security-config
(Maven)
Jul 18, 2023
ProTip!
Advisories are also available from the
GraphQL API