GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,809
Erlang
36
GitHub Actions
31
Go
2,393
Maven
5,000+
npm
4,026
NuGet
720
pip
3,818
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
315 advisories
Filter by severity
XXL-JOB is vulnerable to SSRF attacks
Low
CVE-2025-7787
was published
for
com.xuxueli:xxl-job-core
(Maven)
Jul 18, 2025
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
Low
CVE-2025-27427
was published
for
org.apache.activemq:artemis-server
(Maven)
Apr 1, 2025
Apache Hadoop: Temporary File Local Information Disclosure
Low
CVE-2024-23454
was published
for
org.apache.hadoop:hadoop-common
(Maven)
Sep 25, 2024
XXL SSO is vulnerable to an Open Redirect through malicious manipulation of the redirect_url argument
Low
CVE-2025-6701
was published
for
com.xuxueli:xxl-sso
(Maven)
Jun 26, 2025
Jenkins User1st uTester Plugin vulnerability exposes unencrypted token to authenticated users
Low
CVE-2025-53678
was published
for
io.jenkins.plugins:user1st-utester
(Maven)
Jul 9, 2025
Jenkins Testsigma Test Plan vulnerability exposes API keys via job configuration form
Low
CVE-2025-53661
was published
for
io.jenkins.plugins:testsigma
(Maven)
Jul 9, 2025
Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
Low
CVE-2024-56128
was published
for
org.apache.kafka:kafka_2.10
(Maven)
Dec 18, 2024
PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion
Low
CVE-2025-48059
was published
for
com.powsybl:powsybl-contingency-api
(Maven)
Jun 19, 2025
Alkacon OpenCMS XSS via New User module
Low
CVE-2019-11818
was published
for
org.opencms:opencms-core
(Maven)
May 24, 2022
Alkacon OpenCMS XSS via title and requestedResource parameters
Low
CVE-2013-4600
was published
for
org.opencms:opencms-core
(Maven)
May 17, 2022
Alkacon OpenCMS XSS via homelink, workplaceresource, mode and query parameters
Low
CVE-2015-2351
was published
for
org.opencms:opencms-core
(Maven)
May 14, 2022
Alkacon OpenCMS XSS via searchfilter parameter in system/workplace/admin/workplace/sessions.jsp
Low
CVE-2008-1753
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCMS XSS via searchfilter or listSearchFilter parameter
Low
CVE-2008-1510
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon Open CMS XSS via Logfile Viewer Settings function
Low
CVE-2008-1300
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCMS XSS via file tree navigation in system/workplace/views/explorer/tree_files.jsp
Low
CVE-2008-1045
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCms XSS via query parameter in a search action
Low
CVE-2006-2571
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCms XSS via unsanitized message body
Low
CVE-2006-3933
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCms XSS via username during login
Low
CVE-2005-4294
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
PowSyBl Core XML Reader allows XXE and SSRF
Low
CVE-2025-47293
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
Apache SeaTunnel: Unauthenticated insecure access
Low
CVE-2025-32896
was published
for
org.apache.seatunnel:seatunnel-engine-common
(Maven)
Jun 19, 2025
Spring Cloud Contract vulnerable to local information disclosure
Low
CVE-2024-22236
was published
for
org.springframework.cloud:spring-cloud-contract-shade
(Maven)
Jan 31, 2024
Spring Framework DataBinder Case Sensitive Match Exception
Low
CVE-2025-22233
was published
for
org.springframework:spring-context
(Maven)
May 16, 2025
Apache Tomcat - CGI security constraint bypass
Low
CVE-2025-46701
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 29, 2025
Jenkins BigPanda Notifier Plugin Missing Password Field Masking
Low
CVE-2022-41248
was published
for
org.jenkins-ci.plugins:bigpanda-jenkins
(Maven)
Sep 22, 2022
Fess has Insecure Temporary File Permissions
Low
CVE-2025-48382
was published
for
org.codelibs.fess:fess
(Maven)
May 27, 2025
ProTip!
Advisories are also available from the
GraphQL API