GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,701
Maven
5,000+
npm
4,328
NuGet
761
pip
4,103
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,013 advisories
Filter by severity
Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource
Moderate
CVE-2025-43808
was published
for
com.liferay.commerce:com.liferay.commerce.product.type.virtual.service
(Maven)
Sep 19, 2025
Liferay has a stored cross-site scripting (XSS) vulnerability via a a publication’s “Name” text field
Moderate
CVE-2025-43807
was published
for
com.liferay:com.liferay.change.tracking.service
(Maven)
Sep 22, 2025
Liferay Portal and DXP allows users to add a note to a different virtual instance
Moderate
CVE-2025-43810
was published
for
com.liferay.commerce:com.liferay.commerce.service
(Maven)
Sep 23, 2025
Liferay Portal and DXP audit events record password reminder answers
Moderate
CVE-2025-43814
was published
for
com.liferay:com.liferay.portal.security.audit.event.generators.user.management
(Maven)
Sep 23, 2025
Liferay Portal and DXP does not properly check permission with import and export tasks
Moderate
CVE-2025-43806
was published
for
com.liferay:com.liferay.batch.engine.service
(Maven)
Sep 23, 2025
WSO2 carbon-apimgt affected by an authenticated stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-4760
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api
(Maven)
Sep 23, 2025
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Moderate
CVE-2025-59822
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 23, 2025
WSO2 Identity Server Apps allows content spoofing in logs
Moderate
CVE-2024-6429
was published
for
org.wso2.identity.apps:authentication-portal
(Maven)
Sep 23, 2025
Liferay Portal and DXP does not properly expire sessions
Moderate
CVE-2025-43819
was published
for
com.liferay:com.liferay.saml.impl
(Maven)
Sep 24, 2025
Apache IoTDB: DoS Vulnerability
Moderate
CVE-2025-48392
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Sep 24, 2025
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Moderate
CVE-2025-58457
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Sep 24, 2025
Liferay Portal and DXP vulnerable to a memory leak
Moderate
CVE-2025-43816
was published
for
com.liferay:com.liferay.portal.vulcan.impl
(Maven)
Sep 25, 2025
Liferay Portal vulnerable to reflected cross-site scripting on the page configuration page
Moderate
CVE-2025-43815
was published
for
com.liferay:com.liferay.product.navigation.control.menu.web
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
Moderate
CVE-2025-43813
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameter
Moderate
CVE-2025-43817
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
Moderate
CVE-2025-43818
was published
for
com.liferay:com.liferay.calendar.web
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
Moderate
CVE-2025-43820
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the related asset selector
Moderate
CVE-2025-43811
was published
for
com.liferay:com.liferay.item.selector.web
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the web content template
Moderate
CVE-2025-43812
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal Vulnerable to IDOR via audit events
Moderate
CVE-2025-43827
was published
for
com.liferay:com.liferay.portal.security.audit.storage.service
(Maven)
Sep 30, 2025
Liferay Portal Vulnerable to XSS in Web Content translation
Moderate
CVE-2025-43826
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 1, 2025
QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing
Moderate
CVE-2025-11226
was published
for
ch.qos.logback:logback-core
(Maven)
Oct 1, 2025
Liferay Portal exposes sensitive user data through its Freemarker template
Moderate
CVE-2025-43825
was published
for
com.liferay:com.liferay.portal.template.freemarker
(Maven)
Oct 4, 2025
Liferay Profile Widget does not prevent vCard extension spoofing
Moderate
CVE-2025-43824
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 7, 2025
Liferay Portal is vulnerable to XSS through its Commerce Search Result widget
Moderate
CVE-2025-43823
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
ProTip!
Advisories are also available from the
GraphQL API