GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
271 advisories
Filter by severity
Apache StreamPark Improper Input Validation vulnerability
Critical
CVE-2022-46365
was published
for
org.apache.streampark:streampark
(Maven)
Jul 6, 2023
Apache Zeppelin Improper Input Validation vulnerability
Moderate
CVE-2021-28655
was published
for
org.apache.zeppelin:zeppelin
(Maven)
Jul 6, 2023
Apache Any23 vulnerable to excessive memory usage
Moderate
CVE-2023-34150
was published
for
org.apache.any23:apache-any23
(Maven)
Jul 5, 2023
Apache Sling Commons JSON bundle vulnerable to Improper Input Validation
Critical
CVE-2022-47937
was published
for
org.apache.sling:org.apache.sling.commons.json
(Maven)
May 15, 2023
Apache OpenMeetings vulnerable to remote code execution via null-bye injection
High
CVE-2023-29246
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
May 12, 2023
Snowflake JDBC vulnerable to command injection via SSO URL authentication
High
CVE-2023-30535
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Apr 14, 2023
Improper Input Validation In Eclipse BIRT
High
CVE-2023-0100
was published
for
org.eclipse.birt:org.eclipse.birt.report.viewer
(Maven)
Mar 15, 2023
Apache Linkis vulnerable to Exposure of Sensitive Information
Moderate
CVE-2022-44644
was published
for
org.apache.linkis:linkis
(Maven)
Jan 31, 2023
Http4s improperly parses User-Agent and Server headers
High
CVE-2023-22465
was published
for
org.http4s:http4s-core
(Maven)
Jan 6, 2023
Apache DolphinScheduler vulnerable to Improper Input Validation
Critical
CVE-2022-45875
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Jan 4, 2023
Apache Karaf vulnerable to potential code injection
Critical
CVE-2022-40145
was published
for
org.apache.karaf:apache-karaf
(Maven)
Dec 21, 2022
lite-server vulnerable to Denial of Service
High
CVE-2022-25940
was published
for
lite-server
(Maven)
Dec 20, 2022
Apache CXF vulnerable to Exposure of Sensitive Information
High
CVE-2022-46363
was published
for
org.apache.cxf:cxf-core
(Maven)
Dec 13, 2022
SnakeYaml Constructor Deserialization Remote Code Execution
High
CVE-2022-1471
was published
for
org.yaml:snakeyaml
(Maven)
Dec 12, 2022
TERASOLUNA Server Framework vulnerable to ClassLoader manipulation
High
CVE-2022-43484
was published
for
org.terasoluna.gfw:terasoluna-gfw-common
(Maven)
Dec 5, 2022
Apache Commons Net vulnerable to information leakage via malicious server
Moderate
CVE-2021-37533
was published
for
commons-net:commons-net
(Maven)
Dec 3, 2022
Cross-site Scripting in Apache Hama
High
CVE-2022-45470
was published
for
org.apache.hama:hama-core
(Maven)
Nov 21, 2022
Apache Tomcat may reject request containing invalid Content-Length header
High
CVE-2022-42252
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Nov 1, 2022
Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
Critical
CVE-2022-42468
was published
for
org.apache.flume.flume-ng-sources:flume-jms-source
(Maven)
Oct 26, 2022
MySQL JDBC deserialization vulnerability
Critical
CVE-2022-39312
was published
for
io.dataease:dataease-plugin-common
(Maven)
Oct 18, 2022
protobuf-java has a potential Denial of Service issue
Moderate
CVE-2022-3171
was published
for
com.google.protobuf:protobuf-java
(RubyGems)
Oct 4, 2022
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
Moderate
CVE-2022-24280
was published
for
org.apache.pulsar:pulsar
(Maven)
Sep 25, 2022
Duplicate Advisory: Keycloak user may register themselves with same email ID of any existing user
Moderate
GHSA-j9xq-j329-2xvg
was published
for
org.keycloak:keycloak-core
(Maven)
Aug 27, 2022
•
withdrawn
Remote code execution in Apache Flume
Critical
CVE-2022-34916
was published
for
org.apache.flume.flume-ng-sources:flume-jms-source
(Maven)
Aug 22, 2022
Jetty invalid URI parsing may produce invalid HttpURI.authority
Low
CVE-2022-2047
was published
for
org.eclipse.jetty:jetty-http
(Maven)
Jul 7, 2022
ProTip!
Advisories are also available from the
GraphQL API