GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            335 advisories
        Filter by severity
        
      
      
    
                    
                      In Bouncy Castle JCE Provider the other party DH public key is not fully validated
                    
                      
  Low
                    
                
                      
                        CVE-2016-1000346
                      
                      was published
                        for
                        
                          org.bouncycastle:bcprov-jdk14
                        
                        (Maven)
                      Oct 17, 2018 
                    
                  
                    
                      Low severity vulnerability that affects      org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service
                    
                      
  Low
                    
                
                      
                        CVE-2014-0228
                      
                      was published
                        for
                        
                          org.apache.hive:hive
                        
                        (Maven)
                      Nov 21, 2018 
                    
                  
                    
                      Incorrect Permission Assignment for Critical Resource in Apache hive
                    
                      
  Low
                    
                
                      
                        CVE-2018-1315
                      
                      was published
                        for
                        
                          org.apache.hive:hive
                        
                        (Maven)
                      Nov 21, 2018 
                    
                  
                    
                      Exposure of Sensitive Information to an Unauthorized Actor in Apache hive
                    
                      
  Low
                    
                
                      
                        CVE-2018-1284
                      
                      was published
                        for
                        
                          org.apache.hive:hive
                        
                        (Maven)
                      Nov 21, 2018 
                    
                  
                    
                      Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml
                    
                      
  Low
                    
                
                      
                        CVE-2019-3772
                      
                      was published
                        for
                        
                          org.springframework.integration:spring-integration-ws
                        
                        (Maven)
                      Jan 25, 2019 
                    
                  
                    
                      Low severity vulnerability that affects org.springframework.batch:spring-batch-core
                    
                      
  Low
                    
                
                      
                        CVE-2019-3774
                      
                      was published
                        for
                        
                          org.springframework.batch:spring-batch-core
                        
                        (Maven)
                      Jan 25, 2019 
                    
                  
                    
                      Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Ratpack
                    
                      
  Low
                    
                
                      
                        CVE-2019-11808
                      
                      was published
                        for
                        
                          io.ratpack:ratpack-groovy
                        
                        (Maven)
                      May 14, 2019 
                    
                  
                    
                      Request smuggling is possible when both chunked TE and content length specified
                    
                      
  Low
                    
                
                      
                        CVE-2020-5207
                      
                      was published
                        for
                        
                          io.ktor:ktor-client-cio
                        
                        (Maven)
                      Jan 27, 2020 
                    
                  
                    
                      Password Hashing: Do not use MD5
                    
                      
  Low
                    
                
                      
                        CVE-2020-5229
                      
                      was published
                        for
                        
                          org.opencastproject:opencast-common-jpa-impl
                        
                        (Maven)
                      Jan 30, 2020 
                    
                  
                    
                      Improper validation of certificate with host mismatch in Apache Log4j SMTP appender
                    
                      
  Low
                    
                
                      
                        CVE-2020-9488
                      
                      was published
                        for
                        
                          org.apache.logging.log4j:log4j
                        
                        (Maven)
                      Jun 5, 2020 
                    
                  
                    
                      XSS in Mapfish Print relating to JSONP support
                    
                      
  Low
                    
                
                      
                        CVE-2020-15231
                      
                      was published
                        for
                        
                          org.mapfish.print:print-lib
                        
                        (Maven)
                      Jul 7, 2020 
                    
                  
                    
                      Users with SCRIPT right can execute arbitrary code in XWiki
                    
                      
  Low
                    
                
                      
                        CVE-2020-15171
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-oldcore
                        
                        (Maven)
                      Sep 10, 2020 
                    
                  
                    
                      personnummer/java vulnerable to Improper Input Validation
                    
                      
  Low
                    
                
                      
                        GHSA-q3vw-4jx3-rrr2
                      
                      was published
                        for
                        
                          dev.personnummer:personnummer
                        
                        (Maven)
                      Sep 23, 2020 
                    
                  
                    
                      Memory exhaustion in http4s-async-http-client with large or malicious compressed responses
                    
                      
  Low
                    
                
                      
                        GHSA-8hxh-r6f7-jf45
                      
                      was published
                        for
                        
                          org.http4s:http4s-async-http-client_2.12
                        
                        (Maven)
                      Oct 16, 2020 
                    
                  
                    
                      Key Caching behavior in the DynamoDB Encryption Client.
                    
                      
  Low
                    
                
                      
                        GHSA-w736-hf9p-qqh3
                      
                      was published
                        for
                        
                          com.amazonaws:aws-dynamodb-encryption-java
                        
                        (Maven)
                      Feb 8, 2021 
                    
                  
                    
                      Unencrypted passwords
                    
                      
  Low
                    
                
                      
                        GHSA-q594-2475-8v9f
                      
                      was published
                        for
                        
                          org.apache.nifi:nifi-standard-processors
                        
                        (Maven)
                      Feb 24, 2021 
                        •
                        
                          withdrawn
                    
                  
                    
                      Local Information Disclosure Vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2021-21331
                      
                      was published
                        for
                        
                          com.datadoghq:datadog-api-client
                        
                        (Maven)
                      Mar 3, 2021 
                    
                  
                    
                      Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory
                    
                      
  Low
                    
                
                      
                        CVE-2021-21363
                      
                      was published
                        for
                        
                          io.swagger:swagger-codegen
                        
                        (Maven)
                      Mar 11, 2021 
                    
                  
                    
                      Privilege Context Switching Error in Elasticsearch
                    
                      
  Low
                    
                
                      
                        CVE-2020-7020
                      
                      was published
                        for
                        
                          org.elasticsearch:elasticsearch
                        
                        (Maven)
                      Mar 18, 2021 
                    
                  
                    
                      It's possible to execute anything with the rights of the author of a macro which uses the {{wikimacrocontent}} macro
                    
                      
  Low
                    
                
                      
                        CVE-2021-21379
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-rendering-wikimacro-store
                        
                        (Maven)
                      Mar 23, 2021 
                    
                  
                    
                      Information Disclosure in Guava
                    
                      
  Low
                    
                
                      
                        CVE-2020-8908
                      
                      was published
                        for
                        
                          com.google.guava:guava
                        
                        (Maven)
                      Mar 25, 2021 
                    
                  
                    
                      Discovery uses the same AES/GCM Nonce throughout the session
                    
                      
  Low
                    
                
                      
                        GHSA-w3hj-wr2q-x83g
                      
                      was published
                        for
                        
                          tech.pegasys.discovery:discovery
                        
                        (Maven)
                      Apr 6, 2021 
                    
                  
                    
                      Directory exposure in jetty
                    
                      
  Low
                    
                
                      
                        CVE-2021-28163
                      
                      was published
                        for
                        
                          org.eclipse.jetty:jetty-deploy
                        
                        (Maven)
                      Apr 6, 2021 
                    
                  
                    
                      Potential sensitive data exposure in applications using Vaadin 15
                    
                      
  Low
                    
                
                      
                        GHSA-76f4-fw33-6j2v
                      
                      was published
                        for
                        
                          com.vaadin:vaadin-bom
                        
                        (Maven)
                      Apr 19, 2021 
                    
                  
                    
                      Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11
                    
                      
  Low
                    
                
                      
                        GHSA-3h5r-928v-mxhh
                      
                      was published
                        for
                        
                          com.vaadin:vaadin-bom
                        
                        (Maven)
                      Apr 19, 2021 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API