GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
799 advisories
Filter by severity
Remote code injection in Log4j
Critical
GHSA-94g7-hpv8-h9qm
was published
for
com.splunk.logging:splunk-library-javalogging
(Maven)
Dec 14, 2021
Files Accessible to External Parties in Opencast
Critical
CVE-2021-43821
was published
for
org.opencastproject:opencast-ingest-service-impl
(Maven)
Dec 14, 2021
Apache Log4j Remote Code Execution
Critical
GHSA-mf4f-j588-5xm8
was published
for
org.opencastproject:opencast-common
(Maven)
Dec 14, 2021
Incomplete fix for Apache Log4j vulnerability
Critical
CVE-2021-45046
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Dec 14, 2021
Remote code injection in Log4j (through pax-logging-log4j2)
Critical
GHSA-xxfh-x98p-j8fr
was published
for
org.ops4j.pax.logging:pax-logging-log4j2
(Maven)
Dec 10, 2021
Remote code injection in Log4j
Critical
CVE-2021-44228
was published
for
com.guicedee.services:log4j-core
(Maven)
Dec 10, 2021
Improperly Controlled Modification of Dynamically-Determined Object Attributes in Apache Struts
Critical
CVE-2019-0230
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 2, 2021
Incorrect Default Permissions in Apache JSPWiki
Critical
CVE-2021-44140
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Nov 29, 2021
Exposure of sensitive information in Apache Ozone
Critical
CVE-2021-39231
was published
for
org.apache.ozone:ozone-main
(Maven)
Nov 23, 2021
Incorrect Authorization in Apache Ozone
Critical
CVE-2021-39233
was published
for
org.apache.ozone:ozone-main
(Maven)
Nov 23, 2021
Improper Privilege Management in Apache Ozone
Critical
CVE-2021-36372
was published
for
org.apache.ozone:ozone-main
(Maven)
Nov 23, 2021
Improper Authentication in Apache ShenYu Admin
Critical
CVE-2021-37580
was published
for
org.apache.shenyu:shenyu-admin
(Maven)
Nov 17, 2021
Critical vulnerability found in cron-utils
Critical
CVE-2021-41269
was published
for
com.cronutils:cron-utils
(Maven)
Nov 15, 2021
Improper Verification of Cryptographic Signature in starkbank-ecdsa
Critical
CVE-2021-43570
was published
for
com.starkbank.ellipticcurve:starkbank-ecdsa
(Maven)
Nov 10, 2021
Template injection in thymeleaf-spring5
Critical
CVE-2021-43466
was published
for
org.thymeleaf:thymeleaf-spring5
(Maven)
Nov 10, 2021
Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm
Critical
CVE-2021-40865
was published
for
org.apache.storm:storm
(Maven)
Oct 27, 2021
Command injection leading to Remote Code Execution in Apache Storm
Critical
CVE-2021-38294
was published
for
org.apache.storm:storm
(Maven)
Oct 27, 2021
Policies not properly enforced in OWASP Java HTML Sanitizer
Critical
CVE-2021-42575
was published
for
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
(Maven)
Oct 19, 2021
Expression injection in AviatorScript
Critical
CVE-2021-41862
was published
for
com.googlecode.aviator:aviator
(Maven)
Oct 4, 2021
Deserialization of Untrusted Data in org.apache.ddlutils:ddlutils
Critical
CVE-2021-41616
was published
for
org.apache.ddlutils:ddlutils
(Maven)
Oct 4, 2021
Remote code execution in UReport
Critical
CVE-2020-21125
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Sep 20, 2021
Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
Critical
CVE-2021-41303
was published
for
org.apache.shiro:shiro-core
(Maven)
Sep 20, 2021
Remote Code Execution in Any23
Critical
CVE-2021-40146
was published
for
org.apache.any23:apache-any23
(Maven)
Sep 13, 2021
XML Injection in Any23
Critical
CVE-2021-38555
was published
for
org.apache.any23:apache-any23
(Maven)
Sep 13, 2021
Security check skip in Apache Dubbo
Critical
CVE-2021-37579
was published
for
org.apache.dubbo:dubbo
(Maven)
Sep 10, 2021
ProTip!
Advisories are also available from the
GraphQL API