Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,871 advisories

Loading
Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel Moderate
CVE-2024-25150 was published for com.liferay.portal:release.dxp.bom (Maven) Feb 20, 2024
Liferay Vulnerable to Open Redirect via Adaptive Media Administration Page Moderate
CVE-2023-44308 was published for com.liferay:com.liferay.adaptive.media.web (Maven) Feb 20, 2024
Liferay Portal and Liferay DXP Vulnerable to Open Redirect in Countries Management's Edit Region Page Moderate
CVE-2023-5190 was published for com.liferay.portal:release.dxp.bom (Maven) Feb 20, 2024
Privilege escalation in Liferay Portal Moderate
CVE-2022-45320 was published for com.liferay.portal:release.portal.bom (Maven) Feb 20, 2024
Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file Moderate
CVE-2024-26308 was published for org.apache.commons:commons-compress (Maven) Feb 19, 2024
oscerd astashys
Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file Moderate
CVE-2024-25710 was published for org.apache.commons:commons-compress (Maven) Feb 19, 2024
oscerd anonymous-nlp-student
Absolute path traversal vulnerability in digdag server Moderate
CVE-2024-25125 was published for io.digdag:digdag-server (Maven) Feb 14, 2024
p-
Undertow Path Traversal vulnerability Moderate
CVE-2024-1459 was published for io.undertow:undertow-core (Maven) Feb 12, 2024
OrangeDog
Apache Solr's Streaming Expressions allow users to extract data from other Solr Clouds Moderate
CVE-2023-50298 was published for org.apache.solr:solr-solrj (Maven) Feb 9, 2024
DanielRuf
Micronaut management endpoints vulnerable to drive-by localhost attack Moderate
CVE-2024-23639 was published for io.micronaut:micronaut-http-server (Maven) Feb 9, 2024
Liferay Portal denial-of-service vulnerability Moderate
CVE-2024-25144 was published for com.liferay.portal:release.dxp.bom (Maven) Feb 8, 2024
Liferay Portal allows attackers to discover the existence of sites Moderate
CVE-2024-25146 was published for com.liferay.portal:release.dxp.bom (Maven) Feb 8, 2024
Liferay Portal's account lockout does not invalidate existing user sessions Moderate
CVE-2023-47798 was published for com.liferay.portal:release.dxp.bom (Maven) Feb 8, 2024
Graylog session fixation vulnerability through cookie injection Moderate
CVE-2024-24823 was published for org.graylog2:graylog2-server (Maven) Feb 7, 2024
fabsx00
Apache Ozone Improper Authentication vulnerability Moderate
CVE-2023-39196 was published for org.apache.ozone:ozone-main (Maven) Feb 7, 2024
Spring Security's spring-security.xsd file is world writable Moderate
CVE-2023-34042 was published for org.springframework.security:spring-security-config (Maven) Feb 6, 2024
Malicious input can provoke XSS when preserving comments Moderate
CVE-2024-23635 was published for org.owasp.antisamy:antisamy (Maven) Feb 2, 2024
spassarop leeN
rbri davewichers
Duplicate Advisory: Central Dogma Authentication Bypass Vulnerability via Session Leakage Moderate
GHSA-qfv2-3p2f-vg48 was published for com.linecorp.centraldogma:centraldogma-server (Maven) Feb 2, 2024 withdrawn
CrateDB database has an arbitrary file read vulnerability Moderate
CVE-2024-24565 was published for io.crate:crate (Maven) Jan 30, 2024
Tu0Laj1
Shared projects are unconditionally discovered by Jenkins GitLab Branch Source Plugin Moderate
CVE-2024-23901 was published for io.jenkins.plugins:gitlab-branch-source (Maven) Jan 24, 2024
Path traversal vulnerability in Jenkins Matrix Project Plugin Moderate
CVE-2024-23900 was published for org.jenkins-ci.plugins:matrix-project (Maven) Jan 24, 2024
CSRF vulnerability in Jenkins GitLab Branch Source Plugin Moderate
CVE-2024-23902 was published for io.jenkins.plugins:gitlab-branch-source (Maven) Jan 24, 2024
Cross-site Scripting in JFinal Moderate
CVE-2024-22497 was published for com.jfinal:jfinal (Maven) Jan 23, 2024
Cross-site Scripting in JFinal Moderate
CVE-2024-22496 was published for com.jfinal:jfinal (Maven) Jan 23, 2024
Cross-site Scripting in beetl-bbs Moderate
CVE-2024-22490 was published for com.ibeetl:beetl (Maven) Jan 23, 2024
ProTip! Advisories are also available from the GraphQL API