Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,932 advisories

Loading
Spring-Kafka has Java Deserialization vulnerability When Improperly Configured High
CVE-2023-34040 was published for org.springframework.kafka:spring-kafka (Maven) Aug 24, 2023
moon2263
XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action High
CVE-2023-40572 was published for org.xwiki.platform:xwiki-platform-oldcore (Maven) Aug 23, 2023
Apache XML Graphics Batik Server-Side Request Forgery vulnerability High
CVE-2022-44729 was published for org.apache.xmlgraphics:batik-bridge (Maven) Aug 22, 2023
Nacos Spring vulnerable to Unsafe Deserialization High
CVE-2023-39106 was published for com.alibaba.nacos:nacos-spring-context (Maven) Aug 21, 2023
Apache Ivy External Entity Reference vulnerability High
CVE-2022-46751 was published for org.apache.ivy:ivy (Maven) Aug 21, 2023
OpenNMS vulnerable to remote code execution High
CVE-2023-40313 was published for org.opennms:opennms-base-assembly (Maven) Aug 17, 2023
PowerJob incorrect access control vulnerability High
CVE-2023-36106 was published for tech.powerjob:powerjob (Maven) Aug 17, 2023
Jenkins Shortcut Job Plugin stored cross-site scripting vulnerability High
CVE-2023-40346 was published for io.jenkins.plugins:shortcut-job (Maven) Aug 16, 2023
Jenkins Flaky Test Handler Plugin stored cross-site scripting vulnerability High
CVE-2023-40342 was published for org.jenkins-ci.plugins:flaky-test-handler (Maven) Aug 16, 2023
Jenkins Docker Swarm Plugin stored cross-site scripting vulnerability High
CVE-2023-40350 was published for org.jenkins-ci.plugins:docker-swarm (Maven) Aug 16, 2023
Jenkins Folders Plugin cross-site request forgery vulnerability High
CVE-2023-40336 was published for org.jenkins-ci.plugins:cloudbees-folder (Maven) Aug 16, 2023
OpenNMS privilege elevation vulnerability High
CVE-2023-0872 was published for org.opennms:opennms-webapp-rest (Maven) Aug 14, 2023
OpenNMS Horizon XXE Injection Vulnerability High
CVE-2023-0871 was published for org.opennms.core:org.opennms.core.xml (Maven) Aug 11, 2023
xuxueli xxl-job Cross-Site Request Forgery Vulnerability High
CVE-2020-24922 was published for com.xuxueli:xxl-job (Maven) Aug 11, 2023
Denial of service in jackson-dataformats-text High
CVE-2023-3894 was published for com.fasterxml.jackson.dataformat:jackson-dataformats-text (Maven) Aug 8, 2023
Mochis
Cross-site Scripting (XSS) in CrafterCMS High
CVE-2023-4136 was published for org.craftercms:crafter-engine (Maven) Aug 3, 2023
Apache NiFi Code Injection vulnerability High
CVE-2023-36542 was published for org.apache.nifi:nifi-cdc-mysql-bundle (Maven) Jul 29, 2023
Missing authorization in Jenkins Plug-in for ServiceNow High
CVE-2023-3442 was published for io.jenkins.plugins:servicenow-devops (Maven) Jul 26, 2023
Jenkins Stored Cross-site Scripting vulnerability High
CVE-2023-39151 was published for org.jenkins-ci.main:jenkins-core (Maven) Jul 26, 2023
daniel-beck
Paths contain matrix variables bypass decorators High
CVE-2023-38493 was published for com.linecorp.armeria:armeria (Maven) Jul 25, 2023
Arbitrary File Creation in AbstractUnArchiver High
CVE-2023-37460 was published for org.codehaus.plexus:plexus-archiver (Maven) Jul 25, 2023
uriyay-jfrog
JDBC URL bypassing by allowLoadLocalInfileInPath param High
CVE-2023-34434 was published for org.apache.inlong:manager-pojo (Maven) Jul 25, 2023
Hazelcast Executor Services don't check client permissions properly High
CVE-2023-33265 was published for com.hazelcast:hazelcast (Maven) Jul 19, 2023
Apache ShardingSphere-Agent Deserialization of Untrusted Data vulnerability High
CVE-2023-28754 was published for org.apache.shardingsphere:shardingsphere (Maven) Jul 19, 2023
Spring Security's authorization rules can be misconfigured when using multiple servlets High
CVE-2023-34035 was published for org.springframework.security:spring-security-config (Maven) Jul 18, 2023
ProTip! Advisories are also available from the GraphQL API