GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            335 advisories
        Filter by severity
        
      
      
    
                    
                      Apache Tomcat - CGI security constraint bypass
                    
                      
  Low
                    
                
                      
                        CVE-2025-46701
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      May 29, 2025 
                    
                  
                    
                      Apache Tomcat Rewrite rule bypass
                    
                      
  Low
                    
                
                      
                        CVE-2025-31651
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      Apr 28, 2025 
                    
                  
                    
                      Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
                    
                      
  Low
                    
                
                      
                        CVE-2024-6762
                      
                      was published
                        for
                        
                          org.eclipse.jetty:jetty-servlets
                        
                        (Maven)
                      Oct 14, 2024 
                    
                  
                    
                      Keycloak allows access to admin path through flaw
                    
                      
  Low
                    
                
                      
                        CVE-2025-10939
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-quarkus-server
                        
                        (Maven)
                      Oct 28, 2025 
                    
                  
                    
                      Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
                    
                      
  Low
                    
                
                      
                        CVE-2025-55754
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
                    
                      
  Low
                    
                
                      
                        CVE-2025-61795
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Liferay Portal Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page
                    
                      
  Low
                    
                
                      
                        CVE-2025-62255
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.knowledge.base.web
                        
                        (Maven)
                      Oct 23, 2025 
                    
                  
                    
                      Liferay Portal and DXP are Missing Authorization in Collection Provider
                    
                      
  Low
                    
                
                      
                        CVE-2025-62247
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.search.experiences.service
                        
                        (Maven)
                      Oct 22, 2025 
                    
                  
                    
                      Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
                    
                      
  Low
                    
                
                      
                        CVE-2025-11966
                      
                      was published
                        for
                        
                          io.vertx:vertx-web
                        
                        (Maven)
                      Oct 22, 2025 
                    
                  
                    
                      Jetty vulnerable to errant command quoting in CGI Servlet
                    
                      
  Low
                    
                
                      
                        CVE-2023-36479
                      
                      was published
                        for
                        
                          org.eclipse.jetty.ee10:jetty-ee10-servlets
                        
                        (Maven)
                      Sep 14, 2023 
                    
                  
                    
                      WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
                    
                      
  Low
                    
                
                      
                        CVE-2025-1396
                      
                      was published
                        for
                        
                          org.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt
                        
                        (Maven)
                      Sep 26, 2025 
                    
                  
                    
                      Low severity vulnerability that affects org.springframework.batch:spring-batch-core
                    
                      
  Low
                    
                
                      
                        CVE-2019-3774
                      
                      was published
                        for
                        
                          org.springframework.batch:spring-batch-core
                        
                        (Maven)
                      Jan 25, 2019 
                    
                  
                    
                      Liferay DXP Missing Critical Step in Authentication
                    
                      
  Low
                    
                
                      
                        CVE-2025-43798
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.multi.factor.authentication.timebased.otp.web
                        
                        (Maven)
                      Sep 15, 2025 
                    
                  
                    
                      Liferay Portal has External Control of System or Configuration Settings
                    
                      
  Low
                    
                
                      
                        CVE-2025-43792
                      
                      was published
                        for
                        
                          com.liferay.portal:com.liferay.portal.kernel
                        
                        (Maven)
                      Sep 15, 2025 
                    
                  
                    
                      Xuxueli XXL-SSO Cross-site Scripting vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-6700
                      
                      was published
                        for
                        
                          com.xuxueli:xxl-sso
                        
                        (Maven)
                      Jun 26, 2025 
                    
                  
                    
                      Liferay Portal JSON Web Services Direct Class Invocation Enables Service Access Policy Execution
                    
                      
  Low
                    
                
                      
                        CVE-2025-43789
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.comment.web
                        
                        (Maven)
                      Sep 12, 2025 
                    
                  
                    
                      XXL-JOB is vulnerable to SSRF attacks
                    
                      
  Low
                    
                
                      
                        CVE-2025-7787
                      
                      was published
                        for
                        
                          com.xuxueli:xxl-job-core
                        
                        (Maven)
                      Jul 18, 2025 
                    
                  
                    
                      In Bouncy Castle JCE Provider the other party DH public key is not fully validated
                    
                      
  Low
                    
                
                      
                        CVE-2016-1000346
                      
                      was published
                        for
                        
                          org.bouncycastle:bcprov-jdk14
                        
                        (Maven)
                      Oct 17, 2018 
                    
                  
                    
                      Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions
                    
                      
  Low
                    
                
                      
                        CVE-2025-58056
                      
                      was published
                        for
                        
                          io.netty:netty-codec-http
                        
                        (Maven)
                      Sep 4, 2025 
                    
                  
                    
                      Liferay Portal is vulnerable to XSS attack through its Style Book theme
                    
                      
  Low
                    
                
                      
                        CVE-2025-43774
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.frontend.taglib.clay
                        
                        (Maven)
                      Sep 9, 2025 
                    
                  
                    
                      Apache Hadoop: Temporary File Local Information Disclosure
                    
                      
  Low
                    
                
                      
                        CVE-2024-23454
                      
                      was published
                        for
                        
                          org.apache.hadoop:hadoop-common
                        
                        (Maven)
                      Sep 25, 2024 
                    
                  
                    
                      Apache DolphinScheduler Incorrect Default Permissions Vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2024-43166
                      
                      was published
                        for
                        
                          org.apache.dolphinscheduler:dolphinscheduler
                        
                        (Maven)
                      Sep 3, 2025 
                    
                  
                    
                      Opencast has a partial path traversal vulnerability in UI config
                    
                      
  Low
                    
                
                      
                        CVE-2025-55202
                      
                      was published
                        for
                        
                          org.opencastproject:opencast-user-interface-configuration
                        
                        (Maven)
                      Aug 29, 2025 
                    
                  
                    
                      Bouncy Castle for Java has Out-of-Bounds Write Vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-9340
                      
                      was published
                        for
                        
                          org.bouncycastle:bc-fips
                        
                        (Maven)
                      Aug 22, 2025 
                    
                  
                    
                      Liferay Portal Reflected Cross-Site Scripting Vulnerability via Form Container
                    
                      
  Low
                    
                
                      
                        CVE-2025-43753
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.layout.taglib
                        
                        (Maven)
                      Aug 22, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API