GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,950 advisories
Filter by severity
Mammoth is vulnerable to Directory Traversal
Moderate
CVE-2025-11849
was published
for
Mammoth
(Maven)
Oct 17, 2025
Keycloak error_description injection on error pages that can trigger phishing attacks
Moderate
CVE-2025-10044
was published
for
org.keycloak:keycloak-account-ui
(Maven)
Oct 17, 2025
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
Moderate
CVE-2025-41254
was published
for
org.springframework:spring-websocket
(Maven)
Oct 16, 2025
Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
Moderate
CVE-2025-8916
was published
for
org.bouncycastle:bcpkix-fips
(Maven)
Aug 13, 2025
Duplicate Advisory: Keycloak error_description injection on error pages that can trigger phishing attacks
Moderate
GHSA-xmcw-mv9p-7pq2
was published
for
org.keycloak:keycloak-account-ui
(Maven)
Sep 5, 2025
•
withdrawn
GeoIP processor disables SSL certificate validation when downloading databases
Moderate
GHSA-3xgr-h5hq-7299
was published
for
org.opensearch.dataprepper.plugins:geoip-processor
(Maven)
Oct 15, 2025
OpenSearch Data Prepper uses deprecated SSL protocol identifier
Moderate
GHSA-28gg-8qqj-fhh5
was published
for
org.opensearch.dataprepper.plugins:geoip-processor
(Maven)
Oct 15, 2025
Liferay has Incorrect Permission Assignment for Critical Resource
Moderate
CVE-2025-62251
was published
for
com.liferay:com.liferay.site.navigation.menu.item.asset.vocabulary
(Maven)
Oct 14, 2025
Apache Spark has Inadequate Encryption Strength
Moderate
CVE-2025-55039
was published
for
org.apache.spark:spark-network-common_2.12
(Maven)
Oct 15, 2025
Apache Geode web-api is vulnerable to Cross-site Scripting
Moderate
CVE-2024-44088
was published
for
org.apache.geode:geode-web-api
(Maven)
Oct 14, 2025
Eclipse JGit XML External Entity (XXE) Vulnerability
Moderate
CVE-2025-4949
was published
for
org.eclipse.jgit:org.eclipse.jgit
(Maven)
May 21, 2025
Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62252
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 13, 2025
Liferay Mentions Web is Vulnerable to Cross-site Scripting
Moderate
CVE-2025-62246
was published
for
com.liferay:com.liferay.mentions.web
(Maven)
Oct 13, 2025
Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62241
was published
for
com.liferay.commerce:com.liferay.commerce.order.content.web
(Maven)
Oct 13, 2025
Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62242
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Publications is vulnerable to Incorrect Authorization
Moderate
CVE-2025-62243
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62244
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Opencast's Paella Player 7 is vulnerable to Cross-Site Scripting
Moderate
CVE-2025-61788
was published
for
org.opencastproject:opencast-common
(Maven)
Oct 8, 2025
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Moderate
CVE-2025-59822
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 23, 2025
Liferay Portal is vulnerable to CSRF through publication comments
Moderate
CVE-2025-62245
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 10, 2025
Liferay Portal is vulnerable to XSS through its workflow process builder
Moderate
CVE-2025-62239
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
(Maven)
Oct 10, 2025
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
Moderate
CVE-2025-62238
was published
for
com.liferay:com.liferay.account.admin.web
(Maven)
Oct 10, 2025
Liferay Portal Commerce is vulnerable to XSS through account "name" field
Moderate
CVE-2025-62237
was published
for
com.liferay.commerce:com.liferay.commerce.order.web
(Maven)
Oct 10, 2025
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Moderate
CVE-2025-37727
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 10, 2025
Liferay Portal is vulnerable to XSS through its Calendar Events parameters
Moderate
CVE-2025-62240
was published
for
com.liferay:com.liferay.calendar.web
(Maven)
Oct 9, 2025
ProTip!
Advisories are also available from the
GraphQL API