GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12 advisories
Filter by severity
Insecure Default Initialization of Resource in Pivotal Spring Web Flow
Moderate
CVE-2017-4971
was published
for
org.springframework.webflow:spring-webflow
(Maven)
May 13, 2022
Insecure Default Initialization of Resource in Pivotal Spring Web Flow
Moderate
CVE-2017-8039
was published
for
org.springframework.webflow:spring-webflow
(Maven)
May 13, 2022
OpenStack Nova uses insecure keystone middleware tmpdir by default
Moderate
CVE-2013-2030
was published
for
python-keystoneclient
(pip)
May 17, 2022
Apache Isis webconsole module may directly query the database in prototype mode
Moderate
CVE-2022-42467
was published
for
org.apache.isis.core:isis-core
(Maven)
Oct 19, 2022
User data exposure in Apache InLong
Moderate
CVE-2023-31101
was published
for
org.apache.inlong:manager-dao
(Maven)
May 22, 2023
Insecure Default Initialization In Liferay Portal
Moderate
CVE-2023-33949
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Default swagger-ui configuration exposes all files in the module
Moderate
CVE-2024-22207
was published
for
@fastify/swagger-ui
(npm)
Jan 16, 2024
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions
Moderate
CVE-2024-26267
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
CNCF K3s Kubernetes kubelet configuration exposes credentials
Moderate
CVE-2025-46599
was published
for
github.com/k3s-io/k3s
(Go)
Apr 25, 2025
Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
Moderate
CVE-2025-53602
was published
for
io.zipkin:zipkin-server
(Maven)
Jul 4, 2025
Liferay has Insecure Default Initialization of Resource issue
Moderate
CVE-2025-43797
was published
for
com.liferay:com.liferay.site.admin.web
(Maven)
Sep 16, 2025
Jenkins Eggplant Runner Plugin protection mechanism disabled
Moderate
CVE-2025-64135
was published
for
io.jenkins.plugins:eggplant-runner
(Maven)
Oct 29, 2025
ProTip!
Advisories are also available from the
GraphQL API