GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            6,095 advisories
        Filter by severity
        
      
      
    
                    
                      jQuery-UI vulnerable to Cross-site Scripting in dialog closeText
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-7103
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      jquery-ui Tooltip widget vulnerable to XSS
                    
                      
  Moderate
                    
                
                      
                        CVE-2012-6662
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Cross-site Scripting in jquery-ui
                    
                      
  Moderate
                    
                
                      
                        CVE-2010-5312
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Cross-Site Scripting (XSS) in jquery
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-9251
                      
                      was published
                        for
                        
                          jQuery
                        
                        (RubyGems)
                      Jan 22, 2018 
                    
                  
                    
                      High severity vulnerability that affects jquery-ui
                    
                      
  High
                    
                
                      
                        GHSA-g8q2-24jh-5hpc
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Jul 27, 2018 
                        •
                        
                          withdrawn
                    
                  
                    
                      Bootstrap Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-14041
                      
                      was published
                        for
                        
                          bootstrap
                        
                        (RubyGems)
                      Sep 13, 2018 
                    
                  
                    
                      Bootstrap Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-14042
                      
                      was published
                        for
                        
                          bootstrap
                        
                        (RubyGems)
                      Sep 13, 2018 
                    
                  
                    
                      Spark allows remote attackers to read arbitrary files via a .. (dot dot) in the URI
                    
                      
  High
                    
                
                      
                        CVE-2016-9177
                      
                      was published
                        for
                        
                          com.sparkjava:spark-core
                        
                        (Maven)
                      Oct 4, 2018 
                    
                  
                    
                      Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
                    
                      
  High
                    
                
                      
                        CVE-2016-9878
                      
                      was published
                        for
                        
                          org.springframework:spring-webmvc
                        
                        (Maven)
                      Oct 4, 2018 
                    
                  
                    
                      Dom4j contains a XML Injection vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2018-1000632
                      
                      was published
                        for
                        
                          dom4j:dom4j
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      jackson-databind is vulnerable to a deserialization flaw
                    
                      
  Critical
                    
                
                      
                        CVE-2017-7525
                      
                      was published
                        for
                        
                          com.fasterxml.jackson.core:jackson-databind
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization
                    
                      
  Critical
                    
                
                      
                        CVE-2017-3159
                      
                      was published
                        for
                        
                          org.apache.camel:camel-snakeyaml
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      ZipSlip in org.apache.storm:storm-core
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-8008
                      
                      was published
                        for
                        
                          org.apache.storm:storm-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Spring Framework Cross Site Tracing (XST)
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-11039
                      
                      was published
                        for
                        
                          org.springframework:spring-web
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.springframework:spring-core
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-11040
                      
                      was published
                        for
                        
                          org.springframework:spring-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Access and integrity issue within Eclipse Jetty
                    
                      
  High
                    
                
                      
                        CVE-2018-12538
                      
                      was published
                        for
                        
                          org.eclipse.jetty:jetty-server
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
                    
                      
  High
                    
                
                      
                        CVE-2018-1000180
                      
                      was published
                        for
                        
                          org.bouncycastle:bcprov-jdk14
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      FasterXML jackson-databind allows unauthenticated remote code execution 
                    
                      
  Critical
                    
                
                      
                        CVE-2018-7489
                      
                      was published
                        for
                        
                          com.fasterxml.jackson.core:jackson-databind
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Struts REST Plugin can potentially allow a DoS attack
                    
                      
  High
                    
                
                      
                        CVE-2018-1327
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-rest-plugin
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal
                    
                      
  Critical
                    
                
                      
                        CVE-2017-12611
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.apache.struts:struts2-rest-plugin
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-15707
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-rest-plugin
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Struts Improper Input Validation vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-7672
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Spring AOP functionality (Struts) vulnerable to DoS attack
                    
                      
  High
                    
                
                      
                        CVE-2017-9787
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      The REST Plugin in Apache Struts is using an outdated XStream library
                    
                      
  High
                    
                
                      
                        CVE-2017-9793
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-rest-plugin
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API