GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
46 advisories
Filter by severity
Vaadin Platform possible file bypass via upload validation on the server-side
Moderate
GHSA-c7v7-rqfm-f44j
was published
for
com.vaadin:vaadin
(Maven)
Sep 4, 2025
Vaadin Flow Components possible file bypass via upload validation on the server-side
Moderate
GHSA-94g8-xv23-7656
was published
for
com.vaadin:vaadin-upload-flow
(Maven)
Sep 4, 2025
Vaadin Framework possible file bypass via upload validation on the server-side
Moderate
CVE-2025-9467
was published
for
com.vaadin:vaadin-server
(Maven)
Sep 4, 2025
Unrestricted Upload of File with Dangerous Type Apache Tomcat
High
CVE-2017-12617
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 14, 2022
Liferay Portal allows unrestricted upload of file in the style books component
Moderate
CVE-2025-43766
was published
for
com.liferay:com.liferay.style.book.web
(Maven)
Aug 23, 2025
Liferay Portal Unvalidated File Upload
Moderate
CVE-2025-43750
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.web
(Maven)
Aug 20, 2025
Apache Struts file upload logic is flawed
Critical
CVE-2024-53677
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 11, 2024
Erupt Unrestricted Upload of File with Dangerous Type vulnerability
Moderate
CVE-2025-45855
was published
for
xyz.erupt:erupt
(Maven)
Jun 3, 2025
MCMS allows arbitrary file uploads in the ueditor component
Critical
CVE-2025-29287
was published
for
net.mingsoft:ms-mcms
(Maven)
Apr 21, 2025
Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
High
CVE-2023-50386
was published
for
org.apache.solr:solr-core
(Maven)
Feb 9, 2024
Apache StreamPipes has potential remote code execution (RCE) via file upload
High
CVE-2024-31411
was published
for
org.apache.streampipes:streampipes-parent
(Maven)
Jul 17, 2024
Apache Linkis Zip Slip issue
Critical
CVE-2023-27603
was published
for
org.apache.linkis:linkis
(Maven)
Jul 6, 2023
Apache Linkis Unrestricted File Upload vulnerability
Critical
CVE-2023-27602
was published
for
org.apache.linkis:linkis
(Maven)
Jul 6, 2023
Apache StreamPark Path Traversal vulnerability
Critical
CVE-2022-45802
was published
for
org.apache.streampark:streampark-common_2.11
(Maven)
Jul 6, 2023
Improper Input Validation in Apache ActiveMQ
Critical
CVE-2016-3088
was published
for
org.apache.activemq:activemq-client
(Maven)
May 14, 2022
When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server
High
CVE-2017-12615
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 17, 2018
Arbitrary file upload vulnerability in GeoServer's REST Coverage Store API
High
CVE-2023-51444
was published
for
org.geoserver:gs-platform
(Maven)
Mar 20, 2024
mingSoft MCMS File Upload vulnerability
High
CVE-2024-22567
was published
for
net.mingsoft:ms-mcms
(Maven)
Feb 5, 2024
Jenkins temporary uploaded file created with insecure permissions
Low
CVE-2023-43497
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 20, 2023
jeecg-boot unrestricted file upload vulnerability
Moderate
CVE-2023-34660
was published
for
org.jeecgframework.boot:jeecg-boot-parent
(Maven)
Jun 16, 2023
MCMS vulnerable to arbitrary code execution via crafted thumbnail
High
CVE-2020-22755
was published
for
net.mingsoft:ms-mcms
(Maven)
May 8, 2023
Jeecg-Boot CMS arbitrary file upload vulnerability
Critical
CVE-2020-28088
was published
for
org.jeecgframework.boot:jeecg-boot-parent
(Maven)
May 24, 2022
Arbitrary file upload in Mingsoft MCMS
Critical
CVE-2022-23315
was published
for
net.mingsoft:ms-mcms
(Maven)
Jan 22, 2022
Arbitrary File Upload in Mingsoft MCMS
Critical
CVE-2022-22929
was published
for
net.mingsoft:ms-mcms
(Maven)
Jan 22, 2022
Unrestricted Upload of File with Dangerous Type in Apache Struts2
High
CVE-2012-1592
was published
for
org.apache.struts:struts2-core
(Maven)
Apr 23, 2022
ProTip!
Advisories are also available from the
GraphQL API