GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,655
Maven
5,000+
npm
4,284
NuGet
760
pip
4,067
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
291 advisories
Filter by severity
JDBC Driver for SQL Server has improper input validation issue
High
CVE-2025-59250
was published
for
com.microsoft.sqlserver:mssql-jdbc
(Maven)
Oct 14, 2025
QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing
Moderate
CVE-2025-11226
was published
for
ch.qos.logback:logback-core
(Maven)
Oct 1, 2025
MinIO Java Client XML Tag Value Substitution Vulnerability
High
CVE-2025-59952
was published
for
io.minio:minio
(Maven)
Sep 29, 2025
Apache IoTDB: DoS Vulnerability
Moderate
CVE-2025-48392
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Sep 24, 2025
Apache DolphinScheduler vulnerable to Alert Script Attack
High
CVE-2024-43115
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Sep 9, 2025
Vaadin Platform possible file bypass via upload validation on the server-side
Moderate
GHSA-c7v7-rqfm-f44j
was published
for
com.vaadin:vaadin
(Maven)
Sep 4, 2025
Vaadin Flow Components possible file bypass via upload validation on the server-side
Moderate
GHSA-94g8-xv23-7656
was published
for
com.vaadin:vaadin-upload-flow
(Maven)
Sep 4, 2025
Vaadin Framework possible file bypass via upload validation on the server-side
Moderate
CVE-2025-9467
was published
for
com.vaadin:vaadin-server
(Maven)
Sep 4, 2025
Apache CXF: Untrusted JMS configuration can lead to RCE
Moderate
CVE-2025-48913
was published
for
org.apache.cxf:cxf-rt-transports-jms
(Maven)
Aug 8, 2025
Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string
Moderate
CVE-2024-52279
was published
for
org.apache.zeppelin:zeppelin-jdbc
(Maven)
Aug 3, 2025
XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
High
CVE-2025-54385
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jul 25, 2025
Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
High
CVE-2025-50151
was published
for
org.apache.jena:jena
(Maven)
Jul 21, 2025
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Moderate
CVE-2025-53652
was published
for
org.jenkins-ci.tools:git-parameter
(Maven)
Jul 9, 2025
GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
Critical
CVE-2024-34711
was published
for
org.geoserver.main:gs-main
(Maven)
Jun 10, 2025
Spring Framework DataBinder Case Sensitive Match Exception
Low
CVE-2025-22233
was published
for
org.springframework:spring-context
(Maven)
May 16, 2025
Jenkins DingTalk Plugin Unconditionally Disables SSL/TLS Certificate and Hostname Validation
Moderate
CVE-2025-47888
was published
for
io.jenkins.plugins:dingding-notifications
(Maven)
May 14, 2025
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
High
CVE-2025-22235
was published
for
org.springframework.boot:spring-boot
(Maven)
Apr 28, 2025
Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
Moderate
CVE-2025-31672
was published
for
org.apache.poi:poi-ooxml
(Maven)
Apr 9, 2025
aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
Moderate
CVE-2025-2622
was published
for
com.aizuda:snail-job
(Maven)
Mar 22, 2025
Keycloak allows cross-site scripting (XSS)
Low
CVE-2024-4028
was published
for
org.keycloak:keycloak-core
(Maven)
Feb 18, 2025
SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
High
CVE-2025-24970
was published
for
io.netty:netty-handler
(Maven)
Feb 10, 2025
Apache James vulnerable to denial of service through the use of IMAP literals
High
CVE-2024-37358
was published
for
org.apache.james.protocols:protocols-imap
(Maven)
Feb 6, 2025
Apache Ranger UI vulnerable to Server Side Request Forgery
Critical
CVE-2024-45479
was published
for
org.apache.ranger:ranger
(Maven)
Jan 22, 2025
Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service Page
Moderate
CVE-2024-45478
was published
for
org.apache.ranger:ranger
(Maven)
Jan 22, 2025
sigstore-java has a vulnerability with bundle verification
Low
CVE-2024-54140
was published
for
dev.sigstore:sigstore-java
(Maven)
Dec 5, 2024
ProTip!
Advisories are also available from the
GraphQL API