GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,582
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
77 advisories
Filter by severity
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
CVE-2026-73644
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
High
GHSA-x8mg-6r4p-87pf
was published
for
com.arcadedb:arcadedb-server
(Maven)
Jul 16, 2026
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
Moderate
CVE-2026-49463
was published
for
nl.nl-portal:besluiten
(Maven)
Jul 8, 2026
OpenAM OAuth Authorization Bypass via PKCE Challenge
Moderate
CVE-2026-48717
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jun 29, 2026
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
Critical
CVE-2026-45052
was published
for
org.openidentityplatform.openam:openam-federation-library
(Maven)
Jun 24, 2026
OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC
High
CVE-2026-45048
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jun 23, 2026
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
Moderate
CVE-2026-54683
was published
for
nl.nl-portal:documenten-api
(Maven)
Jun 18, 2026
Apache ActiveMQ server has an incomplete authorization workflow
Moderate
CVE-2026-46605
was published
for
org.apache.activemq:apache-activemq
(Maven)
Jun 1, 2026
Apache Tomcat - Security constraints not correctly applied
Critical
CVE-2026-43515
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 12, 2026
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
High
CVE-2026-3009
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 5, 2026
PSI Probe: Broken access control can lead to DoS
Low
CVE-2026-3269
was published
for
com.github.psi-probe:psi-probe-core
(Maven)
Feb 27, 2026
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
Low
CVE-2026-2733
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 19, 2026
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
High
CVE-2026-22022
was published
for
org.apache.solr:solr-core
(Maven)
Jan 21, 2026
XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view
Critical
CVE-2025-49594
was published
for
org.xwiki.contrib.oidc:oidc-authenticator
(Maven)
Oct 6, 2025
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
Graylog vulnerable to privilege escalation through API tokens
High
CVE-2025-53106
was published
for
org.graylog2:graylog2-server
(Maven)
Jun 30, 2025
XWiki Platform Security Authorization Bridge allows users with just edit right can enforce required rights with programming right
Moderate
CVE-2025-48063
was published
for
org.xwiki.platform:xwiki-platform-security-authorization-bridge
(Maven)
May 21, 2025
The lesscss script service allows cache clearing without programming right
Low
CVE-2025-32972
was published
for
org.xwiki.platform:xwiki-platform-lesscss-script
(Maven)
Apr 29, 2025
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
Moderate
CVE-2025-30373
was published
for
org.graylog2:graylog2-server
(Maven)
Apr 7, 2025
The WikiManager REST API allows any user to create wikis
High
CVE-2025-29926
was published
for
org.xwiki.platform:xwiki-platform-wiki-rest-default
(Maven)
Mar 19, 2025
Incorrect permission check in Jenkins GitLab Plugin allows enumerating credentials IDs
Moderate
CVE-2025-24397
was published
for
org.jenkins-ci.plugins:gitlab-plugin
(Maven)
Jan 22, 2025
Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin
High
CVE-2024-52550
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
Nov 13, 2024
Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
High
CVE-2024-52551
was published
for
org.jenkinsci.plugins:pipeline-model-parent
(Maven)
Nov 13, 2024
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
Critical
CVE-2024-38821
was published
for
org.springframework.security:spring-security-web
(Maven)
Oct 28, 2024
SAK-50571 Sakai Kernel users created with type roleview can login as a normal user
High
CVE-2024-47876
was published
for
org.sakaiproject.kernel:sakai-kernel-impl
(Maven)
Oct 15, 2024
ProTip!
Advisories are also available from the
GraphQL API