GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,950 advisories
Filter by severity
Liferay Portal Commerce Shop is vulnerable to Stored XSS through SVG file
Moderate
CVE-2025-43829
was published
for
com.liferay.commerce:com.liferay.commerce.shop.by.diagram.web
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to XXS through its Commerce Product's Name text field
Moderate
CVE-2025-43821
was published
for
com.liferay.commerce:com.liferay.commerce.product.service
(Maven)
Oct 8, 2025
Liferay Portal has multiple Stored XSS vulnerabilities on its View Order page
Moderate
CVE-2025-43822
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to XSS through its Commerce Search Result widget
Moderate
CVE-2025-43823
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Profile Widget does not prevent vCard extension spoofing
Moderate
CVE-2025-43824
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 7, 2025
Liferay Portal exposes sensitive user data through its Freemarker template
Moderate
CVE-2025-43825
was published
for
com.liferay:com.liferay.portal.template.freemarker
(Maven)
Oct 4, 2025
Liferay Portal Vulnerable to XSS in Web Content translation
Moderate
CVE-2025-43826
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 1, 2025
Liferay Portal Vulnerable to IDOR via audit events
Moderate
CVE-2025-43827
was published
for
com.liferay:com.liferay.portal.security.audit.storage.service
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to reflected cross-site scripting on the page configuration page
Moderate
CVE-2025-43815
was published
for
com.liferay:com.liferay.product.navigation.control.menu.web
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the related asset selector
Moderate
CVE-2025-43811
was published
for
com.liferay:com.liferay.item.selector.web
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the web content template
Moderate
CVE-2025-43812
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
Moderate
CVE-2025-43818
was published
for
com.liferay:com.liferay.calendar.web
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameter
Moderate
CVE-2025-43817
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
Moderate
CVE-2025-43820
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
Moderate
CVE-2025-43813
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 30, 2025
Liferay Portal and DXP vulnerable to a memory leak
Moderate
CVE-2025-43816
was published
for
com.liferay:com.liferay.portal.vulcan.impl
(Maven)
Sep 25, 2025
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Moderate
CVE-2025-58457
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Sep 24, 2025
Apache IoTDB: DoS Vulnerability
Moderate
CVE-2025-48392
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Sep 24, 2025
Liferay Portal and DXP does not properly expire sessions
Moderate
CVE-2025-43819
was published
for
com.liferay:com.liferay.saml.impl
(Maven)
Sep 24, 2025
WSO2 Identity Server Apps allows content spoofing in logs
Moderate
CVE-2024-6429
was published
for
org.wso2.identity.apps:authentication-portal
(Maven)
Sep 23, 2025
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Moderate
CVE-2025-59822
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 23, 2025
WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-4760
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api
(Maven)
Sep 23, 2025
Liferay Portal and DXP allows users to add a note to a different virtual instance
Moderate
CVE-2025-43810
was published
for
com.liferay.commerce:com.liferay.commerce.service
(Maven)
Sep 23, 2025
Liferay Portal and DXP audit events record password reminder answers
Moderate
CVE-2025-43814
was published
for
com.liferay:com.liferay.portal.security.audit.event.generators.user.management
(Maven)
Sep 23, 2025
Liferay Portal and DXP does not properly check permission with import and export tasks
Moderate
CVE-2025-43806
was published
for
com.liferay:com.liferay.batch.engine.service
(Maven)
Sep 23, 2025
ProTip!
Advisories are also available from the
GraphQL API