GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,656 advisories
Filter by severity
Para Server Logs Sensitive Information
Moderate
GHSA-v75g-77vf-6jjq
was published
for
com.erudika:para-server
(Maven)
May 30, 2025
Spring Framework DataBinder Case Sensitive Match Exception
Moderate
CVE-2024-38820
was published
for
org.springframework:spring-context
(Maven)
Oct 18, 2024
Lack of authentication mechanism in Jenkins DotCi Plugin webhook
Moderate
CVE-2022-41238
was published
for
com.groupon.jenkins-ci.plugins:DotCi
(Maven)
Sep 22, 2022
Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting
Moderate
CVE-2021-33339
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2021-33336
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissions
Moderate
CVE-2021-33333
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2021-33332
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Don't Check Permissions of Pages
Moderate
CVE-2021-33324
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Asset Publisher App
Moderate
CVE-2021-29051
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in the Layout Admin Page
Moderate
CVE-2021-29048
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password
Moderate
CVE-2021-29043
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs
Moderate
CVE-2021-33331
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Reveals Data via Overly Verbose Error Messages
Moderate
CVE-2021-29040
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Bypass via Double Encoded URL
Moderate
CVE-2020-15840
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
May 24, 2022
Missing hostname validation in Jenkins View26 Test-Reporting Plugin
Moderate
CVE-2022-41244
was published
for
org.jenkins-ci.plugins:view26
(Maven)
Sep 22, 2022
Jenkins WildFly Deployer Plugin vulnerable to path traversal
Moderate
CVE-2022-41235
was published
for
org.jenkins-ci.plugins:wildfly-deployer
(Maven)
Sep 22, 2022
Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read
Moderate
CVE-2025-27528
was published
for
org.apache.inlong:manager-pojo
(Maven)
May 28, 2025
Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass
Moderate
CVE-2025-27526
was published
for
org.apache.inlong:manager-pojo
(Maven)
May 28, 2025
Elasticsearch Uncaught Exception leading to crash
Moderate
CVE-2024-23449
was published
for
org.elasticsearch:elasticsearch
(Maven)
Mar 29, 2024
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Moderate
CVE-2024-52980
was published
for
org.elasticsearch:elasticsearch
(Maven)
Apr 8, 2025
Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
Moderate
CVE-2024-52981
was published
for
org.elasticsearch:elasticsearch
(Maven)
Apr 8, 2025
io.jmix.rest:jmix-rest allows XSS in the /files Endpoint of the Generic REST API
Moderate
CVE-2025-32951
was published
for
io.jmix.rest:jmix-rest
(Maven)
Apr 22, 2025
io.jmix.localfs:jmix-localfs has a Path Traversal in Local File Storage
Moderate
CVE-2025-32950
was published
for
io.jmix.localfs:jmix-localfs
(Maven)
Apr 22, 2025
io.jmix.localfs:jmix-localfs affected by DoS in the Local File Storage
Moderate
CVE-2025-32952
was published
for
io.jmix.localfs:jmix-localfs
(Maven)
Apr 22, 2025
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Moderate
CVE-2025-26795
was published
for
org.apache.iotdb:iotdb-jdbc
(Maven)
May 14, 2025
ProTip!
Advisories are also available from the
GraphQL API