GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
147 advisories
Filter by severity
org.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalation
Critical
CVE-2023-30537
was published
for
org.xwiki.platform:xwiki-platform-flamingo-theme-ui
(Maven)
Apr 12, 2023
org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
Critical
CVE-2023-29509
was published
for
org.xwiki.platform:xwiki-platform-flamingo-theme-ui
(Maven)
Apr 12, 2023
org.xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability
Critical
CVE-2023-29214
was published
for
org.xwiki.platform:xwiki-platform-panels-ui
(Maven)
Apr 12, 2023
xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability
Critical
CVE-2023-29212
was published
for
org.xwiki.platform:xwiki-platform-panels-ui
(Maven)
Apr 12, 2023
org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerability
Critical
CVE-2023-29211
was published
for
org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
(Maven)
Apr 12, 2023
org.xwiki.platform:xwiki-platform-notifications-ui Eval Injection vulnerability
Critical
CVE-2023-29210
was published
for
org.xwiki.platform:xwiki-platform-notifications-ui
(Maven)
Apr 12, 2023
org.xwiki.platform:xwiki-platform-legacy-notification-activitymacro Eval Injection vulnerability
Critical
CVE-2023-29209
was published
for
org.xwiki.platform:xwiki-platform-legacy-notification-activitymacro
(Maven)
Apr 12, 2023
org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
Critical
CVE-2023-26477
was published
for
org.xwiki.platform:xwiki-platform-flamingo-theme-ui
(Maven)
Mar 3, 2023
Remote Code Execution in com.bstek.uflo:uflo-core
Critical
CVE-2022-25894
was published
for
com.bstek.uflo:uflo-core
(Maven)
Jan 26, 2023
Spring Boot Admins integrated notifier support allows arbitrary code execution
High
CVE-2022-46166
was published
for
de.codecentric:spring-boot-admin
(Maven)
Dec 9, 2022
ff4j is vulnerable to Remote Code Execution (RCE)
Critical
CVE-2022-44262
was published
for
org.ff4j:ff4j-core
(Maven)
Dec 1, 2022
Code injection in quarkus dev ui config editor
Critical
CVE-2022-4116
was published
for
io.quarkus:quarkus-vertx-http-deployment
(Maven)
Nov 22, 2022
Arbitrary code execution in Apache Commons Text
Critical
CVE-2022-42889
was published
for
com.guicedee.services:commons-text
(Maven)
Oct 13, 2022
Apache Pinot has Groovy Function support enabled by default
Critical
CVE-2022-26112
was published
for
org.apache.pinot:pinot
(Maven)
Sep 25, 2022
XWiki Platform Wiki UI Main Wiki Eval Injection vulnerability
Critical
CVE-2022-36099
was published
for
org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
(Maven)
Sep 16, 2022
XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection
Critical
CVE-2022-36100
was published
for
org.xwiki.platform.applications:xwiki-application-tag
(Maven)
Sep 16, 2022
Dataease before 1.11.2 allows arbitrary code execution via crafter plugin
Critical
CVE-2022-34113
was published
for
io.dataease:dataease-plugin-common
(Maven)
Jul 23, 2022
fabric8 kubernetes-client vulnerable
Moderate
CVE-2021-4178
was published
for
io.fabric8:kubernetes-client
(Maven)
Jul 15, 2022
Improper Control of Generation of Code in Jenkins Script Security Plugin
Critical
CVE-2019-10431
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 24, 2022
Improper Control of Generation of Code in Spring Security
Moderate
CVE-2011-2732
was published
for
org.springframework.security:spring-security-core
(Maven)
May 17, 2022
Code injection via property expansion in SoapUI
High
CVE-2014-1202
was published
for
com.smartbear.soapui:soapui
(Maven)
May 17, 2022
Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
High
CVE-2013-1777
was published
for
org.apache.geronimo.framework:geronimo-jmx-remoting
(Maven)
May 17, 2022
Improper Control of Generation of Code in HawtJNI
Moderate
CVE-2013-2035
was published
for
org.fusesource.hawtjni:hawtjni-runtime
(Maven)
May 17, 2022
Jenkins allows for Code Execution via Crafted Packet to the CLI
Moderate
CVE-2014-3666
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Improper Control of Generation of Code ('Code Injection') in Spring Framework
Moderate
CVE-2010-1622
was published
for
org.springframework:spring
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API