GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,848
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
5,833 advisories
Filter by severity
Liferay Portal Reflected XSS in blogs-web
Moderate
CVE-2025-4576
was published
for
com.liferay:com.liferay.blogs.web
(Maven)
Aug 8, 2025
Apache CXF: Untrusted JMS configuration can lead to RCE
Moderate
CVE-2025-48913
was published
for
org.apache.cxf:cxf-rt-transports-jms
(Maven)
Aug 8, 2025
Apache Seata: Deserialization of untrusted Data in Apache Seata Server
High
CVE-2025-53606
was published
for
org.apache.seata:seata-serializer-fury
(Maven)
Aug 8, 2025
Keycloak-services SMTP Inject Vulnerability
Moderate
CVE-2025-8419
was published
for
org.keycloak:keycloak-services
(Maven)
Aug 6, 2025
XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
High
CVE-2025-54125
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Aug 5, 2025
XWiki leaks password hashes and other accessible password properties
High
CVE-2025-54124
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Aug 5, 2025
XWiki allows Reflected XSS in two templates
Moderate
CVE-2025-32430
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Aug 5, 2025
Liferay Portal CAPTCHA Bypass for Gogo Shell
Moderate
CVE-2025-4604
was published
for
com.liferay:com.liferay.captcha.impl
(Maven)
Aug 5, 2025
Apache Zeppelin: XSS in the Helium module
Moderate
CVE-2024-41177
was published
for
org.apache.zeppelin:zeppelin-web
(Maven)
Aug 3, 2025
Apache Zeppelin: Missing Origin Validation in WebSockets vulnerability
Moderate
CVE-2024-51775
was published
for
org.apache.zeppelin:zeppelin-shell
(Maven)
Aug 3, 2025
Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string
Moderate
CVE-2024-52279
was published
for
org.apache.zeppelin:zeppelin-jdbc
(Maven)
Aug 3, 2025
OpenSearch unauthorized data access on fields protected by field level security if field is a member of an object
Moderate
GHSA-2rjv-cv85-xhgm
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Aug 1, 2025
OpenSearch unauthorized data access on fields protected by field masking for fields of type ip, geo_point, geo_shape, xy_point, xy_shape
Moderate
GHSA-rrmm-wq7q-h4v5
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Aug 1, 2025
Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability in the Image Plugin
Moderate
CVE-2025-24854
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jul 31, 2025
Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability via Header Link Rendering
Moderate
CVE-2025-24853
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jul 31, 2025
Apache Struts Extras Before 2 has an Improper Output Neutralization for Logs Vulnerability
Moderate
CVE-2025-54656
was published
for
org.apache.struts:struts-extras
(Maven)
Jul 30, 2025
Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
Moderate
CVE-2025-7784
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
Keycloak phishing attack via email verification step in first login flow
Moderate
CVE-2025-7365
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
Opencast still publishes global system account credentials
Moderate
CVE-2025-54380
was published
for
org.opencastproject:opencast-common
(Maven)
Jul 25, 2025
XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
High
CVE-2025-54385
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jul 25, 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
Critical
CVE-2025-32429
was published
for
org.xwiki.platform:xwiki-platform-distribution-war
(Maven)
Jul 24, 2025
Jakarta Mail vulnerable to SMTP Injection
Moderate
CVE-2025-7962
was published
for
org.eclipse.angus:smtp
(Maven)
Jul 21, 2025
Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
High
CVE-2025-50151
was published
for
org.apache.jena:jena
(Maven)
Jul 21, 2025
Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
Moderate
CVE-2025-49656
was published
for
org.apache.jena:jena-fuseki
(Maven)
Jul 21, 2025
Duplicate Advisory: Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
Moderate
GHSA-83j7-mhw9-388w
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 18, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API