GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,871 advisories
Filter by severity
Cross-site Scripting in OpenCRX
Moderate
CVE-2023-40816
was published
for
org.opencrx:opencrx-core-models
(Maven)
Nov 18, 2023
Cross-site Scripting in OpenCRX
Moderate
CVE-2023-40813
was published
for
org.opencrx:opencrx-core-models
(Maven)
Nov 18, 2023
Cross-site Scripting in OpenCRX
Moderate
CVE-2023-40815
was published
for
org.opencrx:opencrx-core-models
(Maven)
Nov 18, 2023
Cross-site Scripting in OpenCRX
Moderate
CVE-2023-40810
was published
for
org.opencrx:opencrx-core-models
(Maven)
Nov 18, 2023
Cross-site Scripting in OpenCRX
Moderate
CVE-2023-40809
was published
for
org.opencrx:opencrx-core-models
(Maven)
Nov 18, 2023
Cross-site Scripting in OpenCRX
Moderate
CVE-2023-40812
was published
for
org.opencrx:opencrx-core-models
(Maven)
Nov 18, 2023
OpenNMS Cross-site Scripting vulnerability
Moderate
CVE-2023-40314
was published
for
org.opennms:opennms-webapp
(Maven)
Nov 17, 2023
Authenticated users can view job names and groups they do not have authorization to view
Moderate
CVE-2023-47112
was published
for
org.rundeck:rundeckapp
(Maven)
Nov 16, 2023
xxl-job-admin vulnerable to Cross Site Scripting
Moderate
CVE-2023-48088
was published
for
com.xuxueli:xxl-job-admin
(Maven)
Nov 15, 2023
xxl-job-admin vulnerable to Insecure Permissions
Moderate
CVE-2023-48087
was published
for
com.xuxueli:xxl-job-admin
(Maven)
Nov 15, 2023
Duplicate Advisory: Eclipse IDE XXE in eclipse.platform
Moderate
GHSA-cc4w-3cff-j8fw
was published
for
org.eclipse.platform:eclipse.platform
(Maven)
Nov 9, 2023
•
withdrawn
wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moderate
CVE-2023-4061
was published
for
org.wildfly.core:wildfly-controller
(Maven)
Nov 8, 2023
Eclipse Parsson Denial of Service vulnerability
Moderate
CVE-2023-4043
was published
for
org.eclipse.parsson:project
(Maven)
Nov 3, 2023
Eclipse Glassfish remote code execution issue
Moderate
CVE-2023-5763
was published
for
org.glassfish.main.orb:orb-connector
(Maven)
Nov 3, 2023
Elasticsearch vulnerable to stack overflow in the search API
Moderate
CVE-2023-31419
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 26, 2023
Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs
Moderate
CVE-2023-31417
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 26, 2023
org.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documents
Moderate
CVE-2023-37911
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Oct 25, 2023
Jenkins CloudBees CD Plugin vulnerable to arbitrary file read
Moderate
CVE-2023-46655
was published
for
org.jenkins-ci.plugins:electricflow
(Maven)
Oct 25, 2023
Jenkins Warnings Plugin exposures system-scoped credentials
Moderate
CVE-2023-46651
was published
for
io.jenkins.plugins:warnings-ng
(Maven)
Oct 25, 2023
Jenkins lambdatest-automation Plugin missing permission check
Moderate
CVE-2023-46652
was published
for
org.jenkins-ci.plugins:lambdatest-automation
(Maven)
Oct 25, 2023
Withdrawn Advisory: dom4j XML Entity Expansion vulnerability
Moderate
CVE-2023-45960
was published
for
org.dom4j:dom4j
(Maven)
Oct 25, 2023
•
withdrawn
light-oauth2 missing public key verification
Moderate
CVE-2023-31580
was published
for
com.networknt:light-oauth2
(Maven)
Oct 25, 2023
Unsecured WMS dynamic styling sld=<url> parameter affords blind unauthenticated SSRF
Moderate
CVE-2023-41339
was published
for
org.geoserver.web:gs-web-app
(Maven)
Oct 24, 2023
RabbitMQ Java client's Lack of Message Size Limitation leads to Remote DoS Attack
Moderate
CVE-2023-46120
was published
for
com.rabbitmq:amqp-client
(Maven)
Oct 24, 2023
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
Moderate
CVE-2023-44483
was published
for
org.apache.santuario:xmlsec
(Maven)
Oct 20, 2023
ProTip!
Advisories are also available from the
GraphQL API