GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,954 advisories
        Filter by severity
        
      
      
    
                    
                      Jenkins JDepend Plugin vulnerable to XML external entity attacks
                    
                      
  High
                    
                
                      
                        CVE-2025-64134
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:jdepend
                        
                        (Maven)
                      Oct 29, 2025 
                    
                  
                    
                      Jenkins SAML Plugin does not implement a replay cache
                    
                      
  High
                    
                
                      
                        CVE-2025-64131
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:saml
                        
                        (Maven)
                      Oct 29, 2025 
                    
                  
                    
                      Jenkins Azure CLI Plugin does not restrict the commands it executes
                    
                      
  High
                    
                
                      
                        CVE-2025-64140
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:azure-cli
                        
                        (Maven)
                      Oct 29, 2025 
                    
                  
                    
                      Liferay Portal Vulnerable to DoS via Crafted Headless API Request
                    
                      
  High
                    
                
                      
                        CVE-2025-62260
                      
                      was published
                        for
                        
                          com.liferay.portal:release.portal.bom
                        
                        (Maven)
                      Oct 28, 2025 
                    
                  
                    
                      Liferay Portal Vulnerable to CSRF in Headless APIs
                    
                      
  High
                    
                
                      
                        CVE-2025-62258
                      
                      was published
                        for
                        
                          com.liferay.portal:release.portal.bom
                        
                        (Maven)
                      Oct 28, 2025 
                    
                  
                    
                      Keycloak TLS Client-Initiated Renegotiation Denial of Service
                    
                      
  High
                    
                
                      
                        CVE-2025-11419
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-quarkus-dist
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Apache Tomcat Vulnerable to Relative Path Traversal
                    
                      
  High
                    
                
                      
                        CVE-2025-55752
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Apache Syncope allows malicious administrators to inject Groovy code
                    
                      
  High
                    
                
                      
                        CVE-2025-57738
                      
                      was published
                        for
                        
                          org.apache.syncope.core:syncope-core-spring
                        
                        (Maven)
                      Oct 20, 2025 
                    
                  
                    
                      Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system
                    
                      
  High
                    
                
                      
                        CVE-2025-47410
                      
                      was published
                        for
                        
                          org.apache.geode:geode-web
                        
                        (Maven)
                      Oct 18, 2025 
                    
                  
                    
                      Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
                    
                      
  High
                    
                
                      
                        CVE-2025-41253
                      
                      was published
                        for
                        
                          org.springframework.cloud:spring-cloud-gateway-server-webflux
                        
                        (Maven)
                      Oct 16, 2025 
                    
                  
                    
                      OpenSearch Data Prepper plugins trust all SSL certificates by default
                    
                      
  High
                    
                
                      
                        CVE-2025-62371
                      
                      was published
                        for
                        
                          org.opensearch.dataprepper.plugins:opensearch
                        
                        (Maven)
                      Oct 15, 2025 
                    
                  
                    
                      Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
                    
                      
  High
                    
                
                      
                        CVE-2025-59419
                      
                      was published
                        for
                        
                          io.netty:netty-codec-smtp
                        
                        (Maven)
                      Oct 15, 2025 
                    
                  
                    
                      Apache StreamPark contains an Incorrect Execution-Assigned Permissions vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-30001
                      
                      was published
                        for
                        
                          org.apache.streampark:streampark
                        
                        (Maven)
                      Oct 10, 2025 
                    
                  
                    
                      Apache Kylin Authentication Bypass Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-61733
                      
                      was published
                        for
                        
                          org.apache.kylin:kylin
                        
                        (Maven)
                      Oct 2, 2025 
                    
                  
                    
                      Apache Kylin Files or Directories Accessible to External Parties
                    
                      
  High
                    
                
                      
                        CVE-2025-61734
                      
                      was published
                        for
                        
                          org.apache.kylin:kylin
                        
                        (Maven)
                      Oct 2, 2025 
                    
                  
                    
                      Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-61735
                      
                      was published
                        for
                        
                          org.apache.kylin:kylin
                        
                        (Maven)
                      Oct 2, 2025 
                    
                  
                    
                      MinIO Java Client XML Tag Value Substitution Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-59952
                      
                      was published
                        for
                        
                          io.minio:minio
                        
                        (Maven)
                      Sep 29, 2025 
                    
                  
                    
                      Hutool allows remote code execution (RCE) via the QLExpressEngine class
                    
                      
  High
                    
                
                      
                        CVE-2025-56769
                      
                      was published
                        for
                        
                          cn.hutool:hutool-extra
                        
                        (Maven)
                      Sep 26, 2025 
                    
                  
                    
                      Spring Framework annotation detection mechanism may result in improper authorization
                    
                      
  High
                    
                
                      
                        CVE-2025-41249
                      
                      was published
                        for
                        
                          org.springframework:spring-core
                        
                        (Maven)
                      Sep 16, 2025 
                    
                  
                    
                      Spring Security annotation detection mechanism has authorization bypass
                    
                      
  High
                    
                
                      
                        CVE-2025-41248
                      
                      was published
                        for
                        
                          org.springframework.security:spring-security-core
                        
                        (Maven)
                      Sep 16, 2025 
                    
                  
                    
                      Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack
                    
                      
  High
                    
                
                      
                        CVE-2025-43796
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.portal.vulcan.api
                        
                        (Maven)
                      Sep 12, 2025 
                    
                  
                    
                      Liferay Portal is vulnerable to Insecure Direct Object Reference (IDOR) attack through Authentication Bypass
                    
                      
  High
                    
                
                      
                        CVE-2025-43790
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.object.service
                        
                        (Maven)
                      Sep 11, 2025 
                    
                  
                    
                      Apache DolphinScheduler vulnerable to Alert Script Attack
                    
                      
  High
                    
                
                      
                        CVE-2024-43115
                      
                      was published
                        for
                        
                          org.apache.dolphinscheduler:dolphinscheduler
                        
                        (Maven)
                      Sep 9, 2025 
                    
                  
                    
                      XWiki Blog Application: Privilege Escalation (PR) from account through blog content
                    
                      
  High
                    
                
                      
                        CVE-2025-58365
                      
                      was published
                        for
                        
                          org.xwiki.contrib.blog:application-blog-ui
                        
                        (Maven)
                      Sep 8, 2025 
                    
                  
                    
                      Liferay Portal Vulnerable to Denial of Service in Kaleo Forms Admin
                    
                      
  High
                    
                
                      
                        CVE-2025-43772
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.portal.workflow.kaleo.forms.web
                        
                        (Maven)
                      Sep 4, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API