GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,417
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,658
Pub
13
RubyGems
1,027
Rust
1,211
Swift
53
Unreviewed advisories
All unreviewed
5,000+
173 advisories
Filter by severity
Apache Artemis: Unauthorized Temporary Address Creation via OpenWire Protocol
Low
CVE-2026-32642
was published
for
org.apache.activemq:artemis-openwire-protocol
(Maven)
Mar 24, 2026
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
High
CVE-2026-3009
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 5, 2026
Keycloak services allows the issuance of access and refresh tokens for disabled users
Moderate
CVE-2025-14559
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
Liferay Portal and DXP Instance Admin can execute code using Objects Actions and Validations
High
CVE-2025-3586
was published
for
com.liferay:com.liferay.object.service
(Maven)
Dec 12, 2025
Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands
High
CVE-2025-66623
was published
for
io.strimzi:strimzi
(Maven)
Dec 5, 2025
NutzBoot Incorrect Privilege Assignment vulnerability
Moderate
CVE-2025-13806
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
Liferay Portal and DXP do not check permissions of images in a blog entry
Moderate
CVE-2025-62275
was published
for
com.liferay:com.liferay.blogs.item.selector.web
(Maven)
Nov 1, 2025
Liferay Portal Does Not Limit Access to APIs Before Email Verification
Moderate
CVE-2025-62259
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Liferay Publications is vulnerable to Incorrect Authorization
Moderate
CVE-2025-62243
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Portal and DXP does not properly check permission with import and export tasks
Moderate
CVE-2025-43806
was published
for
com.liferay:com.liferay.batch.engine.service
(Maven)
Sep 23, 2025
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
Spring Security annotation detection mechanism has authorization bypass
High
CVE-2025-41248
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 16, 2025
Liferay Portal JSON Web Services Direct Class Invocation Enables Service Access Policy Execution
Low
CVE-2025-43789
was published
for
com.liferay:com.liferay.comment.web
(Maven)
Sep 12, 2025
Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data
Moderate
CVE-2025-43784
was published
for
com.liferay:com.liferay.headless.builder.impl
(Maven)
Sep 10, 2025
XWiki Rendering is vulnerable to RCE attacks when processing nested macros
Critical
CVE-2025-53836
was published
for
org.xwiki.rendering:xwiki-rendering-transformation-macro
(Maven)
Jul 14, 2025
XWiki allows remote code execution through preview of XClass changes in AWM editor
High
CVE-2025-49586
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 13, 2025
WSO2 products vulnerable to privilege escalation due to business logic flaw in SOAP admin services
Moderate
CVE-2024-7096
was published
for
org.wso2.am:am-parent
(Maven)
May 30, 2025
Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users
High
CVE-2025-48881
was published
for
com.ritense.valtimo:object-management
(Maven)
May 28, 2025
Solr script service doesn't take dropped programming right into account
Low
CVE-2025-32971
was published
for
org.xwiki.platform:xwiki-platform-search-solr-api
(Maven)
Apr 29, 2025
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
Low
CVE-2025-27427
was published
for
org.apache.activemq:artemis-server
(Maven)
Apr 1, 2025
XWiki uses the wrong wiki reference in AuthorizationManager
High
CVE-2025-29924
was published
for
org.xwiki.platform:xwiki-platform-security-authorization-api
(Maven)
Mar 19, 2025
WSO2 incorrect authorization vulnerability
Moderate
CVE-2024-2321
was published
for
org.wso2.am:am-parent
(Maven)
Feb 27, 2025
Instaclustr Cassandra-Lucene-Index allows bypass of Cassandra RBAC
High
CVE-2025-26511
was published
for
com.instaclustr:cassandra-lucene-index-plugin
(Maven)
Feb 13, 2025
Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions
Moderate
CVE-2025-24860
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 4, 2025
RuoYi has insecure permissions
Moderate
CVE-2024-57438
was published
for
com.ruoyi:ruoyi
(Maven)
Jan 29, 2025
ProTip!
Advisories are also available from the
GraphQL API