GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,701
Maven
5,000+
npm
4,328
NuGet
761
pip
4,103
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
342 advisories
Filter by severity
Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
Low
CVE-2025-66453
was published
for
org.mozilla:rhino
(Maven)
Dec 3, 2025
Discovery uses the same AES/GCM Nonce throughout the session
Low
CVE-2024-23688
was published
for
tech.pegasys.discovery:discovery
(Maven)
Apr 6, 2021
Keycloak unable to restrict access to the admin console
Low
CVE-2025-10939
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Dec 2, 2025
Duplicate Advisory: Keycloak allows access to admin path through flaw
Low
GHSA-c6cm-5gc7-c3f4
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Oct 28, 2025
•
withdrawn
NutzBoot vulnerable to information disclosure
Low
CVE-2025-13804
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
NutzBoot vulnerable to deserialization
Low
CVE-2025-13805
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
Mustangproject allows exfiltrating files via XXE attacks
Low
CVE-2025-66372
was published
for
org.mustangproject:library
(Maven)
Nov 28, 2025
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
Low
CVE-2025-61795
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Resty has a Path Traversal vulnerability
Low
CVE-2025-13435
was published
for
cn.dreampie:resty
(Maven)
Nov 20, 2025
Apereo CAS code injection vulnerability
Low
CVE-2025-3984
was published
for
org.apereo.cas:cas-management-webapp-support
(Maven)
Apr 27, 2025
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Low
CVE-2025-55754
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Jenkins User1st uTester Plugin vulnerability exposes unencrypted token to authenticated users
Low
CVE-2025-53678
was published
for
io.jenkins.plugins:user1st-utester
(Maven)
Jul 9, 2025
Jenkins Testsigma Test Plan vulnerability exposes API keys via job configuration form
Low
CVE-2025-53661
was published
for
io.jenkins.plugins:testsigma
(Maven)
Jul 9, 2025
Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project
Low
CVE-2024-20925
was published
for
org.openjfx:javafx-media
(Maven)
Feb 17, 2024
Protobuf Maven Plugin protocDigest is ignored when using protoc from PATH
Low
GHSA-j2pc-v64r-mv4f
was published
for
io.github.ascopes:protobuf-maven-plugin
(Maven)
Nov 4, 2025
Apache Tomcat - CGI security constraint bypass
Low
CVE-2025-46701
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 29, 2025
Apache Tomcat Rewrite rule bypass
Low
CVE-2025-31651
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 28, 2025
Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
Low
CVE-2024-6762
was published
for
org.eclipse.jetty:jetty-servlets
(Maven)
Oct 14, 2024
Liferay Portal Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page
Low
CVE-2025-62255
was published
for
com.liferay:com.liferay.knowledge.base.web
(Maven)
Oct 23, 2025
Liferay Portal and DXP are Missing Authorization in Collection Provider
Low
CVE-2025-62247
was published
for
com.liferay:com.liferay.search.experiences.service
(Maven)
Oct 22, 2025
Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
Low
CVE-2025-11966
was published
for
io.vertx:vertx-web
(Maven)
Oct 22, 2025
Jetty vulnerable to errant command quoting in CGI Servlet
Low
CVE-2023-36479
was published
for
org.eclipse.jetty.ee10:jetty-ee10-servlets
(Maven)
Sep 14, 2023
WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
Low
CVE-2025-1396
was published
for
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt
(Maven)
Sep 26, 2025
Low severity vulnerability that affects org.springframework.batch:spring-batch-core
Low
CVE-2019-3774
was published
for
org.springframework.batch:spring-batch-core
(Maven)
Jan 25, 2019
Liferay DXP Missing Critical Step in Authentication
Low
CVE-2025-43798
was published
for
com.liferay:com.liferay.multi.factor.authentication.timebased.otp.web
(Maven)
Sep 15, 2025
ProTip!
Advisories are also available from the
GraphQL API