GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            814 advisories
        Filter by severity
        
      
      
    
                    
                      MCMS vulnerable SQL injection via the content_title parameter
                    
                      
  Critical
                    
                
                      
                        CVE-2025-56316
                      
                      was published
                        for
                        
                          net.mingsoft:ms-mcms
                        
                        (Maven)
                      Oct 17, 2025 
                    
                  
                    
                      XWiki Platform is vulnerable to HQL injection via wiki and space search REST API
                    
                      
  Critical
                    
                
                      
                        CVE-2025-52472
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-rest-server
                        
                        (Maven)
                      Oct 6, 2025 
                    
                  
                    
                      XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view
                    
                      
  Critical
                    
                
                      
                        CVE-2025-49594
                      
                      was published
                        for
                        
                          org.xwiki.contrib.oidc:oidc-authenticator
                        
                        (Maven)
                      Oct 6, 2025 
                    
                  
                    
                      Apache IoTDB: Deserialization of untrusted Data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-48459
                      
                      was published
                        for
                        
                          org.apache.iotdb:iotdb-confignode
                        
                        (Maven)
                      Sep 24, 2025 
                    
                  
                    
                      H2O affected by a deserialization vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-6544
                      
                      was published
                        for
                        
                          ai.h2o:h2o-core
                        
                        (Maven)
                      Sep 22, 2025 
                    
                  
                    
                      jinjava has Sandbox Bypass via JavaType-Based Deserialization
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59340
                      
                      was published
                        for
                        
                          com.hubspot.jinjava:jinjava
                        
                        (Maven)
                      Sep 17, 2025 
                    
                  
                    
                      Spring Expression language property modification using Spring Cloud Gateway Server WebFlux
                    
                      
  Critical
                    
                
                      
                        CVE-2025-41243
                      
                      was published
                        for
                        
                          org.springframework.cloud:spring-cloud-gateway-server-webflux
                        
                        (Maven)
                      Sep 16, 2025 
                    
                  
                    
                      XWiki configuration files can be accessed through jsx and sx endpoints
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55748
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-skin-skinx
                        
                        (Maven)
                      Sep 3, 2025 
                    
                  
                    
                      XWiki configuration files can be accessed through the webjars API
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55747
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-webjars-api
                        
                        (Maven)
                      Sep 3, 2025 
                    
                  
                    
                      Valtimo scripting engine can be used to gain access to sensitive data or resources
                    
                      
  Critical
                    
                
                      
                        CVE-2025-58059
                      
                      was published
                        for
                        
                          com.ritense.valtimo:core
                        
                        (Maven)
                      Aug 28, 2025 
                    
                  
                    
                      Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54988
                      
                      was published
                        for
                        
                          org.apache.tika:tika-parser-pdf-module
                        
                        (Maven)
                      Aug 20, 2025 
                    
                  
                    
                      ExecuTorch integer overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-30404
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch heap buffer overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54949
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch out-of-bounds access vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54950
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch integer overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-30405
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch vulnerable to Heap-based Buffer Overflow
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54951
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
                    
                      
  Critical
                    
                
                      
                        CVE-2025-32429
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-distribution-war
                        
                        (Maven)
                      Jul 24, 2025 
                    
                  
                    
                      XWiki Rendering is vulnerable to RCE attacks when processing nested macros
                    
                      
  Critical
                    
                
                      
                        CVE-2025-53836
                      
                      was published
                        for
                        
                          org.xwiki.rendering:xwiki-rendering-transformation-macro
                        
                        (Maven)
                      Jul 14, 2025 
                    
                  
                    
                      XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
                    
                      
  Critical
                    
                
                      
                        CVE-2025-53835
                      
                      was published
                        for
                        
                          org.xwiki.rendering:xwiki-rendering-syntax-xhtml
                        
                        (Maven)
                      Jul 14, 2025 
                    
                  
                    
                      Conductor vulnerable to OS command injection through unrestricted access to Java classes
                    
                      
  Critical
                    
                
                      
                        CVE-2025-26074
                      
                      was published
                        for
                        
                          org.conductoross:conductor-core
                        
                        (Maven)
                      Jun 30, 2025 
                    
                  
                    
                      Apache Seata Vulnerable to Deserialization of Untrusted Data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-32897
                      
                      was published
                        for
                        
                          org.apache.seata:seata-config-core
                        
                        (Maven)
                      Jun 28, 2025 
                    
                  
                    
                      XWiki allows SQL injection in query endpoint of REST API with Oracle
                    
                      
  Critical
                    
                
                      
                        CVE-2024-56158
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-oldcore
                        
                        (Maven)
                      Jun 12, 2025 
                    
                  
                    
                      GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
                    
                      
  Critical
                    
                
                      
                        CVE-2024-34711
                      
                      was published
                        for
                        
                          org.geoserver.main:gs-main
                        
                        (Maven)
                      Jun 10, 2025 
                    
                  
                    
                      GeoTools has XML External Entity (XXE) Processing Vulnerability in XSD schema handling
                    
                      
  Critical
                    
                
                      
                        GHSA-826p-4gcg-35vw
                      
                      was published
                        for
                        
                          org.geotools:gt-wfs-ng
                        
                        (Maven)
                      Jun 9, 2025 
                    
                  
                    
                      Spring Security authorization bypass for method security annotations on private methods
                    
                      
  Critical
                    
                
                      
                        CVE-2025-41232
                      
                      was published
                        for
                        
                          org.springframework.security:spring-security-aspects
                        
                        (Maven)
                      May 21, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API