GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,779
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,972
NuGet
714
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,893 advisories
Filter by severity
SnakeYaml Constructor Deserialization Remote Code Execution
High
CVE-2022-1471
was published
for
org.yaml:snakeyaml
(Maven)
Dec 12, 2022
Apache Tomcat - DoS in multipart upload
High
CVE-2025-48988
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jun 16, 2025
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
High
CVE-2025-48976
was published
for
org.apache.commons:commons-fileupload2-core
(Maven)
Jun 16, 2025
Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler
High
CVE-2025-3594
was published
for
com.liferay:com.liferay.server.admin.web
(Maven)
Jun 16, 2025
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
High
CVE-2025-3526
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Jun 16, 2025
Liferay Portal does not limit the depth of a GraphQL queries
High
CVE-2025-3602
was published
for
com.liferay:com.liferay.portal.vulcan.impl
(Maven)
Jun 16, 2025
XWiki does not require right warnings for XClass definitions
High
CVE-2025-49585
was published
for
org.xwiki.platform:xwiki-platform-security-requiredrights-default
(Maven)
Jun 13, 2025
XWiki allows remote code execution through preview of XClass changes in AWM editor
High
CVE-2025-49586
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 13, 2025
XWiki makes title of inaccessible pages available through the class property values REST API
High
CVE-2025-49584
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Jun 13, 2025
XWiki allows remote code execution through default value of wiki macro wiki-type parameters
High
CVE-2025-49581
was published
for
org.xwiki.platform:xwiki-platform-rendering-wikimacro-store
(Maven)
Jun 13, 2025
XWiki's required right warnings for macros are incomplete
High
CVE-2025-49582
was published
for
org.xwiki.platform:xwiki-platform-rendering-macro-cache
(Maven)
Jun 13, 2025
XWiki allows privilege escalation through link refactoring
High
CVE-2025-49580
was published
for
org.xwiki.platform:xwiki-platform-refactoring-default
(Maven)
Jun 13, 2025
Undertow Uncontrolled Resource Consumption
High
CVE-2021-3629
was published
for
io.undertow:undertow-core
(Maven)
May 25, 2022
pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
High
CVE-2025-49146
was published
for
org.postgresql:postgresql
(Maven)
Jun 11, 2025
Apache Kafka Deserialization of Untrusted Data vulnerability
High
CVE-2025-27818
was published
for
org.apache.kafka:kafka
(Maven)
Jun 10, 2025
Apache Kafka Deserialization of Untrusted Data vulnerability
High
CVE-2025-27819
was published
for
org.apache.kafka:kafka
(Maven)
Jun 10, 2025
GeoServer vulnerable to SSRF in TestWfsPost for specific targets, e.g. PHP + Nginx
High
GHSA-68cf-j696-wvv9
was published
for
org.geoserver:gs-wfs
(Maven)
Jun 10, 2025
GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint
High
GHSA-2p76-gc46-5fvc
was published
for
org.geonetwork-opensource:gn-web-app
(Maven)
Jun 10, 2025
[XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service
High
CVE-2025-30220
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
Apache InLong Deserialization of Untrusted Data Vulnerability
High
CVE-2025-27531
was published
for
org.apache.inlong:inlong-manager
(Maven)
Jun 6, 2025
GeoServer Infinite Loop Vulnerability in Jiffle process
High
CVE-2025-30145
was published
for
org.geoserver.extension:gs-wps-core
(Maven)
Jun 10, 2025
GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
High
CVE-2024-29198
was published
for
org.geoserver.web:gs-app
(Maven)
Jun 10, 2025
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
High
CVE-2024-12397
was published
for
io.quarkus.http:quarkus-http-core
(Maven)
Dec 12, 2024
Querydsl vulnerable to HQL injection trough orderBy
High
CVE-2024-49203
was published
for
com.querydsl:querydsl-apt
(Maven)
Nov 27, 2024
org.ini4j allows attackers to cause a Denial of Service (DoS)
High
CVE-2022-41404
was published
for
org.ini4j:ini4j
(Maven)
Oct 12, 2022
ProTip!
Advisories are also available from the
GraphQL API