GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,815
Erlang
36
GitHub Actions
32
Go
2,401
Maven
5,000+
npm
4,045
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
5,800 advisories
Filter by severity
Apache Avro Java SDK vulnerable to Improper Input Validation
High
CVE-2023-39410
was published
for
org.apache.avro:avro
(Maven)
Sep 29, 2023
Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability in the Image Plugin
Moderate
CVE-2025-24854
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jul 31, 2025
Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability via Header Link Rendering
Moderate
CVE-2025-24853
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jul 31, 2025
Apache Struts Extras Before 2 has an Improper Output Neutralization for Logs Vulnerability
Moderate
CVE-2025-54656
was published
for
org.apache.struts:struts-extras
(Maven)
Jul 30, 2025
Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
Moderate
CVE-2025-7784
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
Duplicate Advisory: Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
Moderate
GHSA-83j7-mhw9-388w
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 18, 2025
•
withdrawn
Keycloak phishing attack via email verification step in first login flow
Moderate
CVE-2025-7365
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
Duplicate Advisory: Keycloak phishing attack via email verification step in first login flow
Moderate
GHSA-gj52-35xm-gxjh
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 10, 2025
•
withdrawn
Apache Spark UI can allow impersonation if ACLs enabled
High
CVE-2022-33891
was published
for
org.apache.spark:spark-parent_2.12
(Maven)
Jul 19, 2022
Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console
Critical
CVE-2024-8980
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page
High
CVE-2021-29050
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Feb 21, 2024
Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers
Moderate
CVE-2021-29038
was published
for
com.liferay.commerce:com.liferay.commerce.account.web
(Maven)
Feb 21, 2024
Liferay Portal and Liferay DXP User Enumeration Vulnerability
Moderate
CVE-2024-26268
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions
Moderate
CVE-2024-26267
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Two Forward Slashes
Moderate
CVE-2024-25609
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
Moderate
CVE-2024-25608
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Allows Templates to be Viewed via the UI or API
Moderate
CVE-2024-25605
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
Moderate
CVE-2024-25604
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel
Moderate
CVE-2024-25150
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options
Moderate
CVE-2024-25149
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Vulnerable to Open Redirect via Adaptive Media Administration Page
Moderate
CVE-2023-44308
was published
for
com.liferay:com.liferay.adaptive.media.web
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Vulnerable to Open Redirect in Countries Management's Edit Region Page
Moderate
CVE-2023-5190
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Vulnerable to XSS in the Commerce Module
Critical
CVE-2023-42627
was published
for
com.liferay.commerce:com.liferay.commerce.address.content.web
(Maven)
Oct 17, 2023
Liferay Portal and Liferay DXP Vulnerable to XSS in the Wiki Widget
Critical
CVE-2023-42628
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 17, 2023
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
High
CVE-2025-41235
was published
for
org.springframework.cloud:spring-cloud-gateway-server
(Maven)
May 30, 2025
ProTip!
Advisories are also available from the
GraphQL API