GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,935 advisories
Filter by severity
Privilege Defined With Unsafe Actions in Keycloak
High
CVE-2019-10170
was published
for
org.keycloak:keycloak-core
(Maven)
Oct 21, 2021
Missing Release of Resource after Effective Lifetime in Apache Tomcat
High
CVE-2021-42340
was published
for
org.apache.tomcat:tomcat
(Maven)
Oct 15, 2021
Regular expression Denial of Service (ReDoS) in EmailValidator class in V7 compatibility module in Vaadin 8
High
GHSA-jfmf-w293-8xr8
was published
for
com.vaadin:vaadin-bom
(Maven)
Oct 13, 2021
Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustness
High
CVE-2020-8897
was published
for
aws-encryption-sdk
(Maven)
Oct 12, 2021
Improper Authorization in Google OAuth Client
High
CVE-2020-7692
was published
for
com.google.oauth-client:google-oauth-client
(Maven)
Sep 28, 2021
Response Splitting from unsanitized headers
High
CVE-2021-41084
was published
for
org.http4s:http4s-client
(Maven)
Sep 22, 2021
Deserialization of Untrusted Data in com.jsoniter:jsoniter
High
CVE-2021-23441
was published
for
com.jsoniter:jsoniter
(Maven)
Sep 20, 2021
•
withdrawn
Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
High
CVE-2021-40690
was published
for
org.apache.santuario:xmlsec
(Maven)
Sep 20, 2021
Infinite loop in Tomcat due to parsing error
High
CVE-2021-41079
was published
for
org.apache.tomcat:tomcat
(Maven)
Sep 20, 2021
Server-Side Request Forgery in UReport
High
CVE-2020-21122
was published
for
com.bstek.ureport:ureport2-console
(Maven)
Sep 20, 2021
XML External Entity Reference in Apache Jena
High
CVE-2021-39239
was published
for
org.apache.jena:jena-core
(Maven)
Sep 20, 2021
SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way
High
CVE-2021-37137
was published
for
io.netty:netty
(Maven)
Sep 9, 2021
Bzip2Decoder doesn't allow setting size restrictions for decompressed data
High
CVE-2021-37136
was published
for
io.netty:netty
(Maven)
Sep 9, 2021
Remote Code Execution in Apache Dubbo
High
CVE-2021-36162
was published
for
org.apache.dubbo:dubbo
(Maven)
Sep 8, 2021
HTTP header injection in Sonatype Nexus Repository
High
CVE-2021-40143
was published
for
org.sonatype.nexus:nexus-repository
(Maven)
Sep 8, 2021
User impersonation due to incorrect handling of the login JWT
High
CVE-2021-39177
was published
for
org.geysermc:connector
(Maven)
Sep 7, 2021
Authentication bypass in Apache Zeppelin
High
CVE-2020-13929
was published
for
org.apache.zeppelin:zeppelin
(Maven)
Sep 7, 2021
Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server
High
CVE-2021-39133
was published
for
org.rundeck:rundeck-core
(Maven)
Sep 1, 2021
Directory traversal in Eclipse Mojarra
High
CVE-2020-6950
was published
for
org.glassfish:mojarra-parent
(Maven)
Sep 1, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39139
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39141
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
XStream is vulnerable to a Remote Command Execution attack
High
CVE-2021-39144
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39145
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39146
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39147
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
ProTip!
Advisories are also available from the
GraphQL API