GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,932 advisories
Filter by severity
Apollo has potential access control security issue in eureka
High
CVE-2023-25570
was published
for
com.ctrip.framework.apollo:apollo
(Maven)
Feb 22, 2023
Apache Commons FileUpload denial of service vulnerability
High
CVE-2023-24998
was published
for
commons-fileupload:commons-fileupload
(Maven)
Feb 20, 2023
dd-plist XML External Entitly vulnerability
High
CVE-2016-15026
was published
for
com.googlecode.plist:dd-plist
(Maven)
Feb 20, 2023
Cross-Site Request Forgery in Jenkins Azure Credentials Plugin
High
CVE-2023-25767
was published
for
org.jenkins-ci.plugins:azure-credentials
(Maven)
Feb 15, 2023
Privilege escalation in Apache ShenYu
High
CVE-2022-42735
was published
for
org.apache.shenyu:shenyu-admin
(Maven)
Feb 15, 2023
Command injection in Apache Sling
High
CVE-2023-25141
was published
for
org.apache.sling:org.apache.sling.jcr.base
(Maven)
Feb 14, 2023
XML External Entity Reference in ureport
High
CVE-2023-24187
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Feb 14, 2023
Arbitrary code execution in de.tum.in.ase:artemis-java-test-sandbox
High
GHSA-98hq-4wmw-98w9
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Feb 10, 2023
XML External Entity Reference in Apache NiFi
High
CVE-2023-22832
was published
for
org.apache.nifi:nifi-ccda-processors
(Maven)
Feb 10, 2023
Apache Kafka Connect vulnerable to Deserialization of Untrusted Data
High
CVE-2023-25194
was published
for
org.apache.kafka:connect
(Maven)
Feb 7, 2023
Insecure Permissions issue in jeecg-boot
High
CVE-2021-37305
was published
for
org.jeecgframework.boot:jeecg-boot-base
(Maven)
Feb 3, 2023
Insecure Permissions issue in jeecg-boot
High
CVE-2021-37306
was published
for
org.jeecgframework.boot:jeecg-boot-base
(Maven)
Feb 3, 2023
Insecure Permissions issue in jeecg-boot
High
CVE-2021-37304
was published
for
org.jeecgframework.boot:jeecg-boot-base
(Maven)
Feb 3, 2023
Apache InLong contains Out-of-bounds Read vulnerability
High
CVE-2023-24977
was published
for
org.apache.inlong:inlong
(Maven)
Feb 1, 2023
Apache Linkis contains Deserialization of Untrusted Data
High
CVE-2022-44645
was published
for
org.apache.linkis:linkis
(Maven)
Jan 31, 2023
http-cache-semantics vulnerable to Regular Expression Denial of Service
High
CVE-2022-25881
was published
for
http-cache-semantics
(Maven)
Jan 31, 2023
Withdrawn Advisory: Apache IoTDB contains Improper Authentication
High
CVE-2023-24830
was published
for
org.apache.iotdb:iotdb-parent
(Maven)
Jan 30, 2023
•
withdrawn
Arbitrary file write in net.mingsoft:ms-mcms
High
CVE-2022-47042
was published
for
net.mingsoft:ms-mcms
(Maven)
Jan 26, 2023
Sandbox bypass in Jenkins Script Security Plugin
High
CVE-2023-24422
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Jan 26, 2023
CSRF vulnerability in Jenkins Orka Plugin allow capturing credentials
High
CVE-2023-24432
was published
for
io.jenkins.plugins:macstadium-orka
(Maven)
Jan 26, 2023
CSRF vulnerability in Jenkins GitHub Pull Request Builder Plugin
High
CVE-2023-24434
was published
for
org.jenkins-ci.plugins:ghprb
(Maven)
Jan 26, 2023
Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin
High
CVE-2023-24424
was published
for
org.jenkins-ci.plugins:oic-auth
(Maven)
Jan 26, 2023
CSRF vulnerability in Jenkins TestQuality Updater Plugin
High
CVE-2023-24452
was published
for
org.jenkins-ci.plugins:testquality-updater
(Maven)
Jan 26, 2023
Cross-site request forgery vulnerability in Jenkins OpenID Plugin
High
CVE-2023-24446
was published
for
org.jenkins-ci.plugins:openid
(Maven)
Jan 26, 2023
Cross-site request forgery vulnerability in Jenkins RabbitMQ Consumer Plugin
High
CVE-2023-24447
was published
for
org.jenkins-ci.plugins:rabbitmq-consumer
(Maven)
Jan 26, 2023
ProTip!
Advisories are also available from the
GraphQL API