GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,489
Maven
5,000+
npm
4,105
NuGet
735
pip
3,927
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,860 advisories
Filter by severity
Jenkins Applitools Eyes Plugin vulnerability exposes unencrypted keys to certain authenticated users
Moderate
CVE-2025-53742
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
FS2 half-shutdown of socket during TLS handshake may result in spin loop on opposite side
Moderate
CVE-2025-58369
was published
for
co.fs2:fs2-io_0.26
(Maven)
Sep 5, 2025
Vaadin Platform possible file bypass via upload validation on the server-side
Moderate
GHSA-c7v7-rqfm-f44j
was published
for
com.vaadin:vaadin
(Maven)
Sep 4, 2025
Vaadin Flow Components possible file bypass via upload validation on the server-side
Moderate
GHSA-94g8-xv23-7656
was published
for
com.vaadin:vaadin-upload-flow
(Maven)
Sep 4, 2025
Vaadin Framework possible file bypass via upload validation on the server-side
Moderate
CVE-2025-9467
was published
for
com.vaadin:vaadin-server
(Maven)
Sep 4, 2025
Keycloak Potential Variable Reference in Model Storage Services
Moderate
CVE-2025-9162
was published
for
org.keycloak:keycloak-model-storage-services
(Maven)
Aug 21, 2025
Keycloak-services SMTP Inject Vulnerability
Moderate
CVE-2025-8419
was published
for
org.keycloak:keycloak-services
(Maven)
Aug 6, 2025
Netty's decoders vulnerable to DoS via zip bomb style attack
Moderate
CVE-2025-58057
was published
for
io.netty:netty-codec
(Maven)
Sep 3, 2025
Jenkins OpenTelemetry Plugin missing permission check allows capturing credentials
Moderate
CVE-2025-58460
was published
for
io.jenkins.plugins:opentelemetry
(Maven)
Sep 3, 2025
Jenkins global-build-stats Plugin missing permission check can result in graph IDs being enumerated
Moderate
CVE-2025-58459
was published
for
org.jenkins-ci.plugins:global-build-stats
(Maven)
Sep 3, 2025
Jenkins Git client Plugin file system information disclosure vulnerability
Moderate
CVE-2025-58458
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Sep 3, 2025
Bouncy Castle for Java on All (API modules) allows Excessive Allocation
Moderate
CVE-2025-8885
was published
for
org.bouncycastle:bc-fips
(Maven)
Aug 12, 2025
Spoofing attack in swagger-ui
Moderate
CVE-2018-25031
was published
for
org.webjars:swagger-ui
(Maven)
Mar 12, 2022
Regular expression denial of service in apache tika
Moderate
CVE-2022-30126
was published
for
org.apache.tika:tika-core
(Maven)
May 17, 2022
Improper Restriction of XML External Entity Reference in Castor
Moderate
CVE-2014-3004
was published
for
org.castor:castor
(Maven)
May 13, 2022
Silverpeas Core Username Enumeration Vulnerability
Moderate
CVE-2025-46047
was published
for
org.silverpeas.core:silverpeas-core
(Maven)
Sep 2, 2025
Liferay Portal allows improper access through the expandoTableLocalService
Moderate
CVE-2025-43773
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.impl
(Maven)
Aug 29, 2025
Liferay Portal Vulnerable to Cross-Site Scripting in Dynamic Data Mapping
Moderate
CVE-2025-43746
was published
for
ccom.liferay:com.liferay.dynamic.data.mapping.web
(Maven)
Aug 20, 2025
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
Moderate
CVE-2015-5174
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
Moderate
CVE-2015-5345
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
XWiki PDF export jobs store sensitive cookies unencrypted in job statuses
Moderate
CVE-2025-58049
was published
for
org.xwiki.platform:xwiki-platform-export-pdf-api
(Maven)
Aug 28, 2025
Opencast still publishes global system account credentials
Moderate
CVE-2025-54380
was published
for
org.opencastproject:opencast-common
(Maven)
Jul 25, 2025
Searching Opencast may cause a denial of service
Moderate
CVE-2024-52797
was published
for
org.opencastproject:opencast-elasticsearch-impl
(Maven)
Nov 20, 2024
Liferay Portal allows unrestricted upload of file in the style books component
Moderate
CVE-2025-43766
was published
for
com.liferay:com.liferay.style.book.web
(Maven)
Aug 23, 2025
Liferay Portal stored cross-site scripting in text field of the web content structure
Moderate
CVE-2025-43765
was published
for
com.liferay:com.liferay.journal.service
(Maven)
Aug 23, 2025
ProTip!
Advisories are also available from the
GraphQL API