GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,552
Maven
5,000+
npm
4,224
NuGet
746
pip
3,999
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,941 advisories
Filter by severity
Liferay Mentions Web is Vulnerable to Cross-site Scripting
Moderate
CVE-2025-62246
was published
for
com.liferay:com.liferay.mentions.web
(Maven)
Oct 13, 2025
Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62242
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62241
was published
for
com.liferay.commerce:com.liferay.commerce.order.content.web
(Maven)
Oct 13, 2025
Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62252
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 13, 2025
Liferay Publications is vulnerable to Incorrect Authorization
Moderate
CVE-2025-62243
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62244
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Portal is vulnerable to CSRF through publication comments
Moderate
CVE-2025-62245
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 10, 2025
Liferay Portal is vulnerable to XSS through its workflow process builder
Moderate
CVE-2025-62239
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
(Maven)
Oct 10, 2025
Liferay Portal Commerce is vulnerable to XSS through account "name" field
Moderate
CVE-2025-62237
was published
for
com.liferay.commerce:com.liferay.commerce.order.web
(Maven)
Oct 10, 2025
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
Moderate
CVE-2025-62238
was published
for
com.liferay:com.liferay.account.admin.web
(Maven)
Oct 10, 2025
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Moderate
CVE-2025-37727
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 10, 2025
Liferay Portal is vulnerable to XSS through its Calendar Events parameters
Moderate
CVE-2025-62240
was published
for
com.liferay:com.liferay.calendar.web
(Maven)
Oct 9, 2025
Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiers
Moderate
CVE-2025-62228
was published
for
org.apache.flink:flink-cdc-pipeline-connectors
(Maven)
Oct 9, 2025
Keycloak Potential Variable Reference in Model Storage Services
Moderate
CVE-2025-9162
was published
for
org.keycloak:keycloak-model-storage-services
(Maven)
Oct 8, 2025
Opencast's Paella Player 7 is vulnerable to Cross-Site Scripting
Moderate
CVE-2025-61788
was published
for
org.opencastproject:opencast-common
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to Stored XSS through Forms text type field
Moderate
CVE-2025-43830
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Portal Notifications Widget has multiple XSS vulnerabilities through various text fields
Moderate
CVE-2025-43771
was published
for
com.liferay:com.liferay.flags.web
(Maven)
Oct 8, 2025
Liferay Portal Commerce Shop is vulnerable to Stored XSS through SVG file
Moderate
CVE-2025-43829
was published
for
com.liferay.commerce:com.liferay.commerce.shop.by.diagram.web
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to XXS through its Commerce Product's Name text field
Moderate
CVE-2025-43821
was published
for
com.liferay.commerce:com.liferay.commerce.product.service
(Maven)
Oct 8, 2025
Liferay Portal has multiple Stored XSS vulnerabilities on its View Order page
Moderate
CVE-2025-43822
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to XSS through its Commerce Search Result widget
Moderate
CVE-2025-43823
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Profile Widget does not prevent vCard extension spoofing
Moderate
CVE-2025-43824
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 7, 2025
Liferay Portal exposes sensitive user data through its Freemarker template
Moderate
CVE-2025-43825
was published
for
com.liferay:com.liferay.portal.template.freemarker
(Maven)
Oct 4, 2025
Liferay Portal Vulnerable to XSS in Web Content translation
Moderate
CVE-2025-43826
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 1, 2025
Liferay Portal Vulnerable to IDOR via audit events
Moderate
CVE-2025-43827
was published
for
com.liferay:com.liferay.portal.security.audit.storage.service
(Maven)
Sep 30, 2025
ProTip!
Advisories are also available from the
GraphQL API