GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,869 advisories
Filter by severity
Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6484
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
•
withdrawn
Liferay Portal is vulnerable to XSS attacks via its remote app title field
Moderate
CVE-2025-43775
was published
for
com.liferay:com.liferay.client.extension.web
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through its search bar portlet
Moderate
CVE-2025-43781
was published
for
com.liferay:com.liferay.portal.search.web
(Maven)
Sep 9, 2025
Liferay Portal exposes ERC which can lead to exploit the time response attack
Moderate
CVE-2025-43786
was published
for
com.liferay:com.liferay.headless.admin.workflow.impl
(Maven)
Sep 9, 2025
Liferay Portal and Liferay DXP vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-43785
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 10, 2025
FS2 half-shutdown of socket during TLS handshake may result in spin loop on opposite side
Moderate
CVE-2025-58369
was published
for
co.fs2:fs2-io_0.26
(Maven)
Sep 5, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
Moderate
CVE-2025-43776
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 9, 2025
Liferay Portal exposes 500 status when attempting login with a deleted client secret
Moderate
CVE-2025-43777
was published
for
com.liferay:com.liferay.portal.security.sso.openid.connect.impl
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through fieldset name in Kaleo Forms Admin
Moderate
CVE-2025-43778
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.forms.web
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to SSRF through custom object attachment fields
Moderate
CVE-2025-43763
was published
for
com.liferay:com.liferay.object.service
(Maven)
Sep 9, 2025
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2025-58782
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Sep 8, 2025
Jenkins Applitools Eyes Plugin vulnerability exposes unencrypted keys to certain authenticated users
Moderate
CVE-2025-53742
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Vaadin Platform possible file bypass via upload validation on the server-side
Moderate
GHSA-c7v7-rqfm-f44j
was published
for
com.vaadin:vaadin
(Maven)
Sep 4, 2025
Vaadin Flow Components possible file bypass via upload validation on the server-side
Moderate
GHSA-94g8-xv23-7656
was published
for
com.vaadin:vaadin-upload-flow
(Maven)
Sep 4, 2025
Vaadin Framework possible file bypass via upload validation on the server-side
Moderate
CVE-2025-9467
was published
for
com.vaadin:vaadin-server
(Maven)
Sep 4, 2025
Keycloak Potential Variable Reference in Model Storage Services
Moderate
CVE-2025-9162
was published
for
org.keycloak:keycloak-model-storage-services
(Maven)
Aug 21, 2025
Keycloak-services SMTP Inject Vulnerability
Moderate
CVE-2025-8419
was published
for
org.keycloak:keycloak-services
(Maven)
Aug 6, 2025
Netty's decoders vulnerable to DoS via zip bomb style attack
Moderate
CVE-2025-58057
was published
for
io.netty:netty-codec
(Maven)
Sep 3, 2025
Jenkins OpenTelemetry Plugin missing permission check allows capturing credentials
Moderate
CVE-2025-58460
was published
for
io.jenkins.plugins:opentelemetry
(Maven)
Sep 3, 2025
Jenkins global-build-stats Plugin missing permission check can result in graph IDs being enumerated
Moderate
CVE-2025-58459
was published
for
org.jenkins-ci.plugins:global-build-stats
(Maven)
Sep 3, 2025
Jenkins Git client Plugin file system information disclosure vulnerability
Moderate
CVE-2025-58458
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Sep 3, 2025
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
Moderate
CVE-2025-8885
was published
for
org.bouncycastle:bc-fips
(Maven)
Aug 12, 2025
Spoofing attack in swagger-ui
Moderate
CVE-2018-25031
was published
for
org.webjars:swagger-ui
(Maven)
Mar 12, 2022
Regular expression denial of service in apache tika
Moderate
CVE-2022-30126
was published
for
org.apache.tika:tika-core
(Maven)
May 17, 2022
Improper Restriction of XML External Entity Reference in Castor
Moderate
CVE-2014-3004
was published
for
org.castor:castor
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API