Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,933 advisories

Loading
graphql-java vulnerable to Denial of Service via GraphQL query that consumes CPU resources High
CVE-2022-37734 was published for com.graphql-java:graphql-java (Maven) Sep 13, 2022
Goomph before 3.37.2 allows malicious zip file to write contents to arbitrary locations High
CVE-2022-26049 was published for com.diffplug.gradle:goomph (Maven) Sep 12, 2022
Apache James vulnerable to buffering attack High
CVE-2022-28220 was published for org.apache.james:james-server (Maven) Sep 9, 2022
Apache IoTDB grafana-connector contains an interface without authorization High
CVE-2022-38370 was published for org.apache.iotdb:iotdb-grafana-connector (Maven) Sep 6, 2022
Apache ShenYu Admin has insecure permissions High
CVE-2022-37435 was published for org.apache.shenyu:shenyu-common (Maven) Sep 2, 2022
Apache Geode versions deserialization of untrusted datawhen using JMX over RMI on Java 11 High
CVE-2022-37022 was published for org.apache.geode:geode-core (Maven) Sep 1, 2022
Uncontrolled Resource Consumption in snakeyaml High
CVE-2022-25857 was published for org.yaml:snakeyaml (Maven) Aug 31, 2022
wonda-tea-coffee
Keycloak allows anyone to register new security device or key for any user by using WebAuthn password-less login flow High
CVE-2021-3632 was published for org.keycloak:keycloak-core (Maven) Aug 27, 2022
XNIO `notifyReadClosed` method logging message to unexpected end High
CVE-2022-0084 was published for org.jboss.xnio:xnio-all (Maven) Aug 27, 2022
ZK Framework vulnerable to malicious POST High
CVE-2022-36537 was published for org.zkoss.zk:zk (Maven) Aug 27, 2022
tdunlap607
Deserialization of Untrusted Data in Apache Hadoop YARN High
CVE-2021-25642 was published for org.apache.hadoop:hadoop-yarn-server (Maven) Aug 26, 2022
Incorrect implementation of lockout feature in Keycloak High
CVE-2021-3513 was published for org.keycloak:keycloak-parent (Maven) Aug 23, 2022
Improper Privilege Management in com.xuxueli:xxl-job High
CVE-2022-36157 was published for com.xuxueli:xxl-job (Maven) Aug 20, 2022
MarkLee131
Path Traversal in Payara High
CVE-2022-37422 was published for fish.payara.api:payara-bom (Maven) Aug 19, 2022
Mapbox is vulnerable to Integer Overflow High
CVE-2022-38216 was published for com.mapbox.mapboxsdk:mapbox-android-core (Maven) Aug 17, 2022
billyjbryant aruneko
4thline cling uPnP protocol issue can lead to denial of service High
CVE-2020-23622 was published for org.fourthline.cling:cling-core (Maven) Aug 16, 2022
OpenSearch vulnerable to Improper Authorization of Index Containing Sensitive Information High
CVE-2022-35980 was published for org.opensearch.plugin:opensearch-security (Maven) Aug 12, 2022
PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names High
CVE-2022-31197 was published for org.postgresql:postgresql (Maven) Aug 6, 2022
kato-sho JBrown0x90
DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import High
CVE-2022-31195 was published for org.dspace:dspace-api (Maven) Aug 6, 2022
JSPUI vulnerable to path traversal in submission (resumable) upload High
CVE-2022-31194 was published for org.dspace:dspace-jspui (Maven) Aug 6, 2022
JSPUI's controlled vocabulary feature vulnerable to Open Redirect before v6.4 and v5.11 High
CVE-2022-31193 was published for org.dspace:dspace-jspui (Maven) Aug 6, 2022
JSPUI Possible Cross Site Scripting in "Request a Copy" Feature High
CVE-2022-31192 was published for org.dspace:dspace-jspui (Maven) Aug 6, 2022
JSPUI spellcheck and autocomplete tools vulnerable to Cross Site Scripting High
CVE-2022-31191 was published for org.dspace:dspace-jspui (Maven) Aug 6, 2022
Undertow vulnerable to Dos via Large AJP request High
CVE-2022-2053 was published for io.undertow:undertow-core (Maven) Aug 6, 2022
Keycloak allows arbitrary Javascript to be uploaded for SAML protocol mapper even if UPLOAD_SCRIPTS feature disabled High
GHSA-q2gp-gph3-88x9 was published for org.keycloak:keycloak-saml-core (Maven) Aug 6, 2022 withdrawn
ProTip! Advisories are also available from the GraphQL API