GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
37
Go
2,526
Maven
5,000+
npm
4,189
NuGet
742
pip
3,968
Pub
12
RubyGems
947
Rust
1,030
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,907 advisories
Filter by severity
WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-4760
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api
(Maven)
Sep 23, 2025
WSO2 Identity Server Apps allows content spoofing in logs
Moderate
CVE-2024-6429
was published
for
org.wso2.identity.apps:authentication-portal
(Maven)
Sep 23, 2025
Liferay Portal and DXP does not properly expire sessions
Moderate
CVE-2025-43819
was published
for
com.liferay:com.liferay.saml.impl
(Maven)
Sep 24, 2025
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Moderate
CVE-2025-58457
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Sep 24, 2025
Jenkins has a log message injection vulnerability
Moderate
CVE-2025-59476
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 17, 2025
Liferay Portal and DXP vulnerable to a memory leak
Moderate
CVE-2025-43816
was published
for
com.liferay:com.liferay.portal.vulcan.impl
(Maven)
Sep 25, 2025
Apache Batik vulnerable to Server-Side Request Forgery
Moderate
CVE-2022-38648
was published
for
org.apache.xmlgraphics:batik
(Maven)
Sep 23, 2022
Apache Batik Server-Side Request Forgery
Moderate
CVE-2022-38398
was published
for
org.apache.xmlgraphics:batik
(Maven)
Sep 23, 2022
Apache IoTDB: DoS Vulnerability
Moderate
CVE-2025-48392
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Sep 24, 2025
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Moderate
CVE-2025-59822
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 23, 2025
Spring Batch Admin vulnerable to Stored Cross-site scripting (XSS) in the file upload functionality
Moderate
CVE-2017-12882
was published
for
org.springframework.batch:spring-batch-admin-manager
(Maven)
May 17, 2022
Liferay Portal and DXP audit events record password reminder answers
Moderate
CVE-2025-43814
was published
for
com.liferay:com.liferay.portal.security.audit.event.generators.user.management
(Maven)
Sep 23, 2025
Liferay Portal and DXP allows users to add a note to a different virtual instance
Moderate
CVE-2025-43810
was published
for
com.liferay.commerce:com.liferay.commerce.service
(Maven)
Sep 23, 2025
Liferay Portal and DXP does not properly check permission with import and export tasks
Moderate
CVE-2025-43806
was published
for
com.liferay:com.liferay.batch.engine.service
(Maven)
Sep 23, 2025
Timing Attack Vulnerability in SCRAM Authentication
Moderate
CVE-2025-59432
was published
for
com.ongres.scram:scram-common
(Maven)
Sep 16, 2025
Liferay has a stored cross-site scripting (XSS) vulnerability via a a publication’s “Name” text field
Moderate
CVE-2025-43807
was published
for
com.liferay:com.liferay.change.tracking.service
(Maven)
Sep 22, 2025
Keycloak Potential Variable Reference in Model Storage Services
Moderate
CVE-2025-9162
was published
for
org.keycloak:keycloak-model-storage-services
(Maven)
Aug 21, 2025
Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource
Moderate
CVE-2025-43808
was published
for
com.liferay.commerce:com.liferay.commerce.product.type.virtual.service
(Maven)
Sep 19, 2025
Liferay Portal Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-43809
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 19, 2025
Liferay Contacts Center widget has insecure direct object reference
Moderate
CVE-2025-43803
was published
for
com.liferay:com.liferay.contacts.web
(Maven)
Sep 19, 2025
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
Moderate
CVE-2025-53864
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Jul 11, 2025
Jenkins is missing a permission check in the authenticated users' profile menu
Moderate
CVE-2025-59475
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 17, 2025
Jenkins has a missing permission check, allowing users to obtain agent names
Moderate
CVE-2025-59474
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 17, 2025
Keycloak SMTP Inject Vulnerability
Moderate
CVE-2025-8419
was published
for
org.keycloak:keycloak-services
(Maven)
Sep 17, 2025
Duplicate Advisory: Keycloak-services SMTP Inject Vulnerability
Moderate
GHSA-qj5r-2r5p-phc7
was published
for
org.keycloak:keycloak-services
(Maven)
Aug 6, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API