GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,969 advisories
Filter by severity
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39148
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
Improper Handling of Length Parameter Inconsistency in Compress
High
CVE-2021-35516
was published
for
org.apache.commons:commons-compress
(Maven)
Aug 2, 2021
Insecure Deserialization in Apache Commons Beanutils
High
CVE-2019-10086
was published
for
commons-beanutils:commons-beanutils
(Maven)
Jun 15, 2020
WildFly vulnerable to Insecure Default Initialization of Resource
High
CVE-2022-1278
was published
for
org.wildfly.bom:wildfly
(Maven)
Sep 14, 2022
Improper Authorization in Undertoe
High
CVE-2020-1745
was published
for
io.undertow:undertow-core
(Maven)
May 24, 2022
Improper Access Control in Elasticsearch
High
CVE-2015-1427
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Sling Servlets Post
High
CVE-2016-0956
was published
for
org.apache.sling:org.apache.sling.servlets.post
(Maven)
May 14, 2022
Cross-Site Request Forgery in Jenkins
High
CVE-2017-1000356
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Cleartext Transmission of Sensitive Information in Apache MINA
High
CVE-2019-0231
was published
for
org.apache.mina:mina-core
(Maven)
May 24, 2022
Unrestricted Upload of File with Dangerous Type in Sonatype Nexus Repository Manager
High
CVE-2019-16530
was published
for
org.sonatype.nexus:nexus-repository
(Maven)
May 24, 2022
Improper Input Validation in Apache Qpid AMQP 0-x JMS
High
CVE-2016-4974
was published
for
org.apache.qpid:qpid-jms-client
(Maven)
May 14, 2022
XWiki Platform Attachment UI vulnerable to cross-site scripting in the move attachment form
High
CVE-2022-36097
was published
for
org.xwiki.platform:xwiki-platform-attachment-ui
(Maven)
Sep 16, 2022
Incorrect Privilege Assignment in RESTEasy
High
CVE-2014-3490
was published
for
org.jboss.resteasy:resteasy-client
(Maven)
May 14, 2022
Improper Neutralization of Special Elements used in a Command in FitNesse Wiki
High
CVE-2014-1216
was published
for
org.fitnesse:fitnesse
(Maven)
May 17, 2022
Improper Input Validation in Drools and jBPM
High
CVE-2014-8125
was published
for
org.drools:drools-core
(Maven)
May 17, 2022
Improper Restriction of XML External Entity Reference in Apache Solr
High
CVE-2012-6612
was published
for
org.apache.solr:solr-core
(Maven)
May 17, 2022
Deserialization of Untrusted Data in Spring Batch
High
CVE-2020-5411
was published
for
org.springframework.batch:spring-batch-core
(Maven)
May 24, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Directory LDAP API
High
CVE-2015-3250
was published
for
org.apache.directory.api:api-ldap-model
(Maven)
May 17, 2022
Improper Input Validation in Apache Commons Email
High
CVE-2017-9801
was published
for
org.apache.commons:commons-email
(Maven)
May 17, 2022
Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
High
CVE-2021-20218
was published
for
io.fabric8:kubernetes-client
(Maven)
May 24, 2022
AWS CodeDeploy Plugin stored AWS Secret Key in plain text
High
CVE-2018-1000403
was published
for
com.amazonaws:codedeploy
(Maven)
May 13, 2022
Improper Access Control in MySQL Connectors Java
High
CVE-2017-3523
was published
for
mysql:mysql-connector-java
(Maven)
May 13, 2022
Loop with Unreachable Exit Condition in Apache Thrift
High
CVE-2019-0205
was published
for
org.apache.thrift:libthrift
(Maven)
May 24, 2022
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39139
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
Uncaught Exception in jsoup
High
CVE-2021-37714
was published
for
org.jsoup:jsoup
(Maven)
Aug 23, 2021
ProTip!
Advisories are also available from the
GraphQL API