GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            6,100 advisories
        Filter by severity
        
      
      
    
                    
                      Junrar vulnerable to Infinite Loop
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-12418
                      
                      was published
                        for
                        
                          com.github.junrar:junrar
                        
                        (Maven)
                      Oct 17, 2018 
                    
                  
                    
                      Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methods
                    
                      
  High
                    
                
                      
                        CVE-2014-0003
                      
                      was published
                        for
                        
                          org.apache.camel:camel-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Camel's XSLT component allows remote attackers to read arbitrary files
                    
                      
  High
                    
                
                      
                        CVE-2014-0002
                      
                      was published
                        for
                        
                          org.apache.camel:camel-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
                    
                      
  High
                    
                
                      
                        CVE-2017-5643
                      
                      was published
                        for
                        
                          org.apache.camel:camel-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks
                    
                      
  Critical
                    
                
                      
                        CVE-2016-8749
                      
                      was published
                        for
                        
                          org.apache.camel:camel-jackson
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Camel can allow remote attackers to execute arbitrary commands
                    
                      
  High
                    
                
                      
                        CVE-2015-5348
                      
                      was published
                        for
                        
                          org.apache.camel:camel-ahc
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Camel-xstream component in Apache Camel can allow remote attackers to execute arbitrary commands 
                    
                      
  Critical
                    
                
                      
                        CVE-2015-5344
                      
                      was published
                        for
                        
                          org.apache.camel:camel-xstream
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile object
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-0264
                      
                      was published
                        for
                        
                          org.apache.camel:camel-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Camel XML External Entity vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-0263
                      
                      was published
                        for
                        
                          org.apache.camel:camel-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Camel's Mail is vulnerable to path traversal
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-8041
                      
                      was published
                        for
                        
                          org.apache.camel:camel-mail
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache is vulnerable to XXE in XSD validation processor
                    
                      
  Critical
                    
                
                      
                        CVE-2018-8027
                      
                      was published
                        for
                        
                          org.apache.camel:camel-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
                    
                      
  Critical
                    
                
                      
                        CVE-2017-12634
                      
                      was published
                        for
                        
                          org.apache.camel:camel-castor
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Code execution via deserialization in org.apache.ignite:ignite-core
                    
                      
  Critical
                    
                
                      
                        CVE-2018-8018
                      
                      was published
                        for
                        
                          org.apache.ignite:ignite-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache serialization mechanism does not have a list of classes allowed for serialization/deserialization
                    
                      
  Critical
                    
                
                      
                        CVE-2018-1295
                      
                      was published
                        for
                        
                          org.apache.ignite:ignite-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.apache.ignite:ignite-core
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-6805
                      
                      was published
                        for
                        
                          org.apache.ignite:ignite-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Ignite communicates to an external PHP server where sensitive information is sent
                    
                      
  High
                    
                
                      
                        CVE-2017-7686
                      
                      was published
                        for
                        
                          org.apache.ignite:ignite-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects apache axis
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-8032
                      
                      was published
                        for
                        
                          axis:axis
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Improper Validation of Certificates in apache axis
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-3596
                      
                      was published
                        for
                        
                          axis:axis
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents
                    
                      
  High
                    
                
                      
                        CVE-2018-8030
                      
                      was published
                        for
                        
                          org.apache.qpid:apache-qpid-broker-j
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.apache.qpid:proton-j
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-2166
                      
                      was published
                        for
                        
                          org.apache.qpid:proton-j
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Improper Input Validation in org.apache.qpid:qpid-broker
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-3094
                      
                      was published
                        for
                        
                          org.apache.qpid:qpid-broker
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication
                    
                      
  Critical
                    
                
                      
                        CVE-2016-4432
                      
                      was published
                        for
                        
                          org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Moderate severity vulnerability that affects org.apache.juddi:juddi-client
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-5241
                      
                      was published
                        for
                        
                          org.apache.juddi:juddi-client
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering
                    
                      
  High
                    
                
                      
                        CVE-2017-9805
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-rest-plugin
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
                    
                      Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
                    
                      
  High
                    
                
                      
                        CVE-2017-9804
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-core
                        
                        (Maven)
                      Oct 16, 2018 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API