GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,460
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,142
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
284 advisories
Filter by severity
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
Moderate
CVE-2025-32781
was published
for
com.ctrip.framework.apollo:apollo
(Maven)
Jul 13, 2026
OpenRemote read-only asset users can write predicted datapoints
Moderate
CVE-2026-49439
was published
for
io.openremote:openremote-manager
(Maven)
Jul 6, 2026
NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
Moderate
CVE-2026-55414
was published
for
nl.nl-portal:form
(Maven)
Jun 19, 2026
Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints
Moderate
CVE-2026-44595
was published
for
org.yamcs:yamcs-core
(Maven)
May 27, 2026
Jenkins GitHub Branch Source Plugin: Missing permissions check allows attackers to perform a connection test
Moderate
CVE-2026-42522
was published
for
org.jenkins-ci.plugins:github-branch-source
(Maven)
Apr 29, 2026
Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths
Moderate
CVE-2026-42519
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Apr 29, 2026
Jenkins is missing a permission check on password fields
Moderate
CVE-2025-67636
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Dec 10, 2025
BlazeMeter Jenkins Plugin is Missing Authorization for Available Resources
Moderate
CVE-2025-13472
was published
for
com.blazemeter.plugins:BlazeMeterJenkinsPlugin
(Maven)
Dec 3, 2025
XWiki view file macro: User can view content of office file without view rights on the attachment
Moderate
CVE-2025-65089
was published
for
com.xwiki.pro:xwiki-pro-macros-ui
(Maven)
Nov 18, 2025
Jenkins Publish to Bitbucket Plugin is missing a permissions check
Moderate
CVE-2025-64148
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins Publish to Bitbucket Plugin is missing a permissions check
Moderate
CVE-2025-64150
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins Nexus Task Runner Plugin is missing a permission check
Moderate
CVE-2025-64142
was published
for
org.jenkins-ci.plugins:nexus-task-runner
(Maven)
Oct 29, 2025
Jenkins Start Windocks Containers Plugin is missing a permission check
Moderate
CVE-2025-64139
was published
for
org.jenkins-ci.plugins:windocks-start-container
(Maven)
Oct 29, 2025
Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
Moderate
CVE-2025-64132
was published
for
io.jenkins.plugins:mcp-server
(Maven)
Oct 29, 2025
Jenkins Themis Plugin is missing a permission check
Moderate
CVE-2025-64137
was published
for
org.jenkins-ci.plugins:themis
(Maven)
Oct 29, 2025
Liferay Portal and DXP do not properly restrict access to OpenAPI
Moderate
CVE-2025-62256
was published
for
com.liferay:com.liferay.portal.security.auth.verifier
(Maven)
Oct 23, 2025
PowerJob OpenAPIController is missing authorization
Moderate
CVE-2025-11581
was published
for
tech.powerjob:powerjob-server-starter
(Maven)
Oct 10, 2025
PowerJob has Missing Authorization in its /user/list file
Moderate
CVE-2025-11580
was published
for
tech.powerjob:powerjob
(Maven)
Oct 10, 2025
Jenkins has a missing permission check, allowing users to obtain agent names
Moderate
CVE-2025-59474
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 17, 2025
Jenkins is missing a permission check in the authenticated users' profile menu
Moderate
CVE-2025-59475
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 17, 2025
Liferay Portal allows remote attackers to view display page templates via crafted URLs
Moderate
CVE-2025-43805
was published
for
com.liferay:com.liferay.asset.display.page.service
(Maven)
Sep 17, 2025
Liferay Portal's Organization Selector exposes organization data to remote authenticated users
Moderate
CVE-2025-43788
was published
for
com.liferay:com.liferay.organizations.item.selector.web
(Maven)
Sep 12, 2025
Jenkins OpenTelemetry Plugin missing permission check allows capturing credentials
Moderate
CVE-2025-58460
was published
for
io.jenkins.plugins:opentelemetry
(Maven)
Sep 3, 2025
Liferay Portal allows improper access through the expandoTableLocalService
Moderate
CVE-2025-43773
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.impl
(Maven)
Aug 29, 2025
GeoServer Missing Authorization on REST API Index
Moderate
CVE-2025-27505
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
ProTip!
Advisories are also available from the
GraphQL API