GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,511
Maven
5,000+
npm
4,149
NuGet
736
pip
3,949
Pub
12
RubyGems
946
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,935 advisories
Filter by severity
Insertion of Sensitive Information into Log File in Apache NiFi
High
CVE-2020-1942
was published
for
org.apache.nifi:nifi-framework-core
(Maven)
Jan 6, 2022
Server-side request forgery (SSRF) in Apache Batik
High
CVE-2020-11987
was published
for
org.apache.xmlgraphics:batik-svgbrowser
(Maven)
Jan 6, 2022
Sandbox Bypass in Apache Velocity Engine
High
CVE-2020-13936
was published
for
org.apache.velocity:velocity
(Maven)
Jan 6, 2022
Cross-Site Request Forgery in com.softwaremill.akka-http-session:core_2.12
High
CVE-2020-28452
was published
for
com.softwaremill.akka-http-session:core_2.12
(Maven)
Jan 6, 2022
Improper Certificate Validation in Apache IoTDB
High
CVE-2020-1952
was published
for
org.apache.iotdb:iotdb-parent
(Maven)
Jan 6, 2022
Deserialization of Untrusted Data in Apache Heron
High
CVE-2020-1964
was published
for
org.apache.heron:heron-simulator
(Maven)
Jan 6, 2022
ReDOS in Vfsjfilechooser2
High
CVE-2021-29061
was published
for
com.github.fracpete:vfsjfilechooser2
(Maven)
Jan 6, 2022
Infinite loop in Apache CFX
High
CVE-2021-30468
was published
for
org.apache.cxf:apache-cxf
(Maven)
Jan 6, 2022
Improper Authorization in Keycloak
High
CVE-2021-4133
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 6, 2022
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
High
CVE-2021-45105
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Dec 18, 2021
Using JMSAppender in log4j configuration may lead to deserialization of untrusted data
High
GHSA-3w6p-8f82-gw8r
was published
for
ru.yandex.clickhouse:clickhouse-jdbc-bridge
(Maven)
Dec 17, 2021
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to join a target cluster via providing configuration information.
High
CVE-2020-35209
was published
for
io.atomix:atomix
(Maven)
Dec 17, 2021
An issue in Atomix v3.1.5 allows a malicious Atomix node to remove states of ONOS storage via abuse of primitive operations.
High
CVE-2020-35214
was published
for
io.atomix:atomix
(Maven)
Dec 17, 2021
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.
High
CVE-2020-35213
was published
for
io.atomix:atomix
(Maven)
Dec 17, 2021
An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node.
High
CVE-2020-35211
was published
for
io.atomix:atomix
(Maven)
Dec 17, 2021
Improper Restriction of XML External Entity Reference in com.h2database:h2.
High
CVE-2021-23463
was published
for
com.h2database:h2
(Maven)
Dec 16, 2021
Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Apache Sling Commons Messaging Mail
High
CVE-2021-44549
was published
for
org.apache.sling:org.apache.sling.commons.messaging.mail
(Maven)
Dec 16, 2021
Opencast publishes global system account credentials
High
CVE-2018-16153
was published
for
org.opencastproject:opencast-common
(Maven)
Dec 14, 2021
HTTP Method Spoofing
High
CVE-2021-43807
was published
for
org.opencastproject:opencast-common
(Maven)
Dec 14, 2021
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
High
CVE-2021-4104
was published
for
log4j:log4j
(Maven)
Dec 14, 2021
Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit Oak
High
CVE-2020-1940
was published
for
org.apache.jackrabbit:oak-core
(Maven)
Dec 10, 2021
Unsafe Deserialization that can Result in Code Execution
High
CVE-2020-36282
was published
for
com.rabbitmq.jms:rabbitmq-jms
(Maven)
Dec 10, 2021
Denial of Service (DoS) in Jackson Dataformat CBOR
High
CVE-2020-28491
was published
for
com.fasterxml.jackson.dataformat:jackson-dataformat-cbor
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36189
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
Unsafe Deserialization in jackson-databind
High
CVE-2020-36187
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Dec 9, 2021
ProTip!
Advisories are also available from the
GraphQL API