GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,958
Erlang
29
GitHub Actions
16
Go
1,745
Maven
4,971
npm
3,507
NuGet
609
pip
3,066
Pub
10
RubyGems
832
Rust
780
Swift
34
Unreviewed advisories
All unreviewed
5,000+
253 advisories
Filter by severity
Path Traversal in XWiki Platform
Low
CVE-2022-29253
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 1, 2022
Improper Authentication in Apache Hadoop
Low
CVE-2013-2192
was published
for
org.apache.hadoop:hadoop-common
(Maven)
May 17, 2022
Improper Input Validation in Jenkins
Low
CVE-2017-1000401
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Low
CVE-2013-2071
was published
for
org.apache.tomcat:tomcat
(Maven)
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Low
CVE-2017-2603
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
Low
CVE-2017-2651
was published
for
org.jenkins-ci.plugins:mailer
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in JBoss Fuse
Low
CVE-2014-0085
was published
for
org.jboss.fuse:jboss-fuse
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java
Low
CVE-2017-3589
was published
for
mysql:mysql-connector-java
(Maven)
May 13, 2022
Cross-site scripting in Apache Struts
Low
CVE-2006-1548
was published
for
struts:struts
(Maven)
May 1, 2022
Incorrect Default Permissions in Apache Commons FileUpload
Low
CVE-2013-0248
was published
for
commons-fileupload:commons-fileupload
(Maven)
May 5, 2022
A user without PR can reset user authentication failures information
Low
CVE-2021-32729
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-script
(Maven)
Jul 2, 2021
personnummer/java vulnerable to Improper Input Validation
Low
GHSA-q3vw-4jx3-rrr2
was published
for
dev.personnummer:personnummer
(Maven)
Sep 23, 2020
Reflected cross-site scripting in development mode handler in Vaadin
Low
GHSA-8vfw-v2jv-9hwc
was published
for
com.vaadin:flow-server
(Maven)
Jun 28, 2021
Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11
Low
GHSA-3h5r-928v-mxhh
was published
for
com.vaadin:vaadin-bom
(Maven)
Apr 19, 2021
Discovery uses the same AES/GCM Nonce throughout the session
Low
GHSA-w3hj-wr2q-x83g
was published
for
tech.pegasys.discovery:discovery
(Maven)
Apr 6, 2021
Ciphertext Malleability Issue in Tink Java
Low
CVE-2020-8929
was published
for
com.google.crypto.tink:tink
(Maven)
Oct 16, 2020
Key Caching behavior in the DynamoDB Encryption Client.
Low
GHSA-w736-hf9p-qqh3
was published
for
com.amazonaws:aws-dynamodb-encryption-java
(Maven)
Feb 8, 2021
Potential sensitive data exposure in applications using Vaadin 15
Low
GHSA-76f4-fw33-6j2v
was published
for
com.vaadin:vaadin-bom
(Maven)
Apr 19, 2021
Memory exhaustion in http4s-async-http-client with large or malicious compressed responses
Low
GHSA-8hxh-r6f7-jf45
was published
for
org.http4s:http4s-async-http-client_2.12
(Maven)
Oct 16, 2020
Incorrect Permission Assignment for Critical Resource in Apache hive
Low
CVE-2018-1315
was published
for
org.apache.hive:hive
(Maven)
Nov 21, 2018
Low severity vulnerability that affects org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service
Low
CVE-2014-0228
was published
for
org.apache.hive:hive
(Maven)
Nov 21, 2018
XSS in Mapfish Print relating to JSONP support
Low
CVE-2020-15231
was published
for
org.mapfish.print:print-lib
(Maven)
Jul 7, 2020
In Bouncy Castle JCE Provider the other party DH public key is not fully validated
Low
CVE-2016-1000346
was published
for
org.bouncycastle:bcprov-jdk14
(Maven)
Oct 17, 2018
Low severity vulnerability that affects org.springframework.batch:spring-batch-core
Low
CVE-2019-3774
was published
for
org.springframework.batch:spring-batch-core
(Maven)
Jan 25, 2019
Request smuggling is possible when both chunked TE and content length specified
Low
CVE-2020-5207
was published
for
io.ktor:ktor-client-cio
(Maven)
Jan 27, 2020
ProTip!
Advisories are also available from the
GraphQL API