GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
124 advisories
Filter by severity
protobuf-java has potential Denial of Service issue
High
CVE-2024-7254
was published
for
com.google.protobuf:protobuf-java
(RubyGems)
Sep 19, 2024
Apache Struts forced double OGNL evaluation
High
CVE-2016-4461
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
OpenFlow plugin for OpenDaylight LLDP Relay
High
CVE-2015-1612
was published
for
org.opendaylight.openflowplugin:openflowplugin
(Maven)
May 17, 2022
OpenFlow plugin for OpenDaylight allows spoofing the SDN topology
High
CVE-2015-1611
was published
for
org.opendaylight.openflowplugin:openflowplugin
(Maven)
May 17, 2022
lite-server vulnerable to Denial of Service
High
CVE-2022-25940
was published
for
lite-server
(Maven)
Dec 20, 2022
SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
High
CVE-2025-24970
was published
for
io.netty:netty-handler
(Maven)
Feb 10, 2025
mod_cluster Denial of Service vulnerability
High
CVE-2016-3110
was published
for
org.jboss.mod_cluster:mod_cluster-parent
(Maven)
May 14, 2022
Caucho Quercus, as distributed in Resin, does not properly handle unspecified characters in the names of variables
High
CVE-2012-2965
was published
for
com.caucho:resin
(Maven)
May 17, 2022
Apache DolphinScheduler: RCE by arbitrary js execution
High
CVE-2024-29831
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Aug 12, 2024
Jenkins allows Deserialization of Untrusted Data via an XML File
High
CVE-2016-0792
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP Access
High
CVE-2012-4438
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Apr 23, 2022
Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
High
CVE-2023-49299
was published
for
org.apache.dolphinscheduler:dolphinscheduler-master
(Maven)
Dec 30, 2023
Apache UIMA Java SDK Deserialization of Untrusted Data, Improper Input Validation vulnerability
High
CVE-2023-39913
was published
for
org.apache.uima:uimaj
(Maven)
Nov 8, 2023
Apache Avro Java SDK vulnerable to Improper Input Validation
High
CVE-2023-39410
was published
for
avro
(Maven)
Sep 29, 2023
Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated users
High
CVE-2024-23320
was published
for
org.apache.dolphinscheduler:dolphinscheduler-master
(Maven)
Feb 23, 2024
Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
High
CVE-2024-27135
was published
for
org.apache.pulsar:pulsar-functions-worker
(Maven)
Mar 12, 2024
Improper Input Validation in Apache Struts
High
CVE-2006-1547
was published
for
struts:struts
(Maven)
May 1, 2022
Apache James vulnerable to denial of service through the use of IMAP literals
High
CVE-2024-37358
was published
for
org.apache.james.protocols:protocols-imap
(Maven)
Feb 6, 2025
SnakeYaml Constructor Deserialization Remote Code Execution
High
CVE-2022-1471
was published
for
org.yaml:snakeyaml
(Maven)
Dec 12, 2022
Apache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS Proxying
High
CVE-2024-27894
was published
for
org.apache.pulsar:pulsar-functions-worker
(Maven)
Mar 12, 2024
Apache Syncope Improper Input Validation vulnerability
High
CVE-2024-38503
was published
for
org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui
(Maven)
Jul 22, 2024
SMTP smuggling in Apache James
High
CVE-2023-51747
was published
for
org.apache.james:james-server
(Maven)
Feb 27, 2024
Apache DolphinScheduler: Resource File Read And Write Vulnerability
High
CVE-2024-30188
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Aug 12, 2024
Spring Cloud Function Framework vulnerable to Denial of Service
High
CVE-2024-22271
was published
for
org.springframework.cloud:spring-cloud-function-context
(Maven)
Jul 9, 2024
Improper Input Validation in Apache Solr
High
CVE-2019-17558
was published
for
org.apache.solr:solr-core
(Maven)
Feb 12, 2020
ProTip!
Advisories are also available from the
GraphQL API