GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,460
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,142
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
51 advisories
Filter by severity
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
High
CVE-2026-54076
was published
for
com.arcadedb:arcadedb-engine
(Maven)
Jul 16, 2026
GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
High
CVE-2026-46487
was published
for
org.geonetwork-opensource:geonetwork
(Maven)
Jul 1, 2026
Apache NiFi is missing the Restricted annotation with the Execute Code Required Permission
High
CVE-2026-39816
was published
for
org.apache.nifi:nifi-other-graph-services-nar
(Maven)
May 8, 2026
XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
High
CVE-2026-33229
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Apr 8, 2026
Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates
High
CVE-2026-25903
was published
for
org.apache.nifi:nifi-web-api
(Maven)
Feb 17, 2026
Any user with view access to the XWiki space can change the authenticator
High
CVE-2025-46557
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-ui
(Maven)
Apr 30, 2025
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
High
CVE-2025-22235
was published
for
org.springframework.boot:spring-boot
(Maven)
Apr 28, 2025
The WikiManager REST API allows any user to create wikis
High
CVE-2025-29926
was published
for
org.xwiki.platform:xwiki-platform-wiki-rest-default
(Maven)
Mar 19, 2025
Script security bypass vulnerability in Jenkins Shared Library Version Override Plugin
High
CVE-2024-52554
was published
for
io.jenkins.plugins:shared-library-version-override
(Maven)
Nov 13, 2024
Ant Media Server vulnerable to a local privilege escalation
High
CVE-2024-32656
was published
for
io.antmedia:ant-media-server
(Maven)
Apr 22, 2024
Erroneous authentication pass in Spring Security
High
CVE-2024-22257
was published
for
org.springframework.security:spring-security-core
(Maven)
Mar 18, 2024
Jenkins Nexus Platform Plugin missing permission check
High
CVE-2023-50767
was published
for
org.sonatype.nexus.ci:nexus-jenkins-plugin
(Maven)
Dec 13, 2023
Authorization bypass in Quarkus
High
CVE-2023-6394
was published
for
io.quarkus:quarkus-smallrye-graphql-client
(Maven)
Dec 9, 2023
Jenkins MATLAB Plugin missing permission checks
High
CVE-2023-49654
was published
for
org.jenkins-ci.plugins:matlab
(Maven)
Nov 29, 2023
Authenticated Rundeck users can view or delete jobs they do not have authorization for.
High
CVE-2023-48222
was published
for
org.rundeck:rundeck
(Maven)
Nov 16, 2023
org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Move
High
CVE-2023-37910
was published
for
org.xwiki.platform:xwiki-platform-attachment-api
(Maven)
Oct 25, 2023
Disabled permissions granted by Jenkins Assembla Auth Plugin
High
CVE-2023-41945
was published
for
org.jenkins-ci.plugins:assembla-auth
(Maven)
Sep 6, 2023
Missing authorization in Jenkins Plug-in for ServiceNow
High
CVE-2023-3442
was published
for
io.jenkins.plugins:servicenow-devops
(Maven)
Jul 26, 2023
Hazelcast Executor Services don't check client permissions properly
High
CVE-2023-33265
was published
for
com.hazelcast:hazelcast
(Maven)
Jul 19, 2023
Missing authorization in Liferay portal
High
CVE-2023-33948
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Command injection in nevado-jms
High
CVE-2023-31826
was published
for
org.skyscreamer:nevado-jms
(Maven)
May 23, 2023
Apache James server's JMX management service vulnerable to privilege escalation by local user
High
CVE-2023-26269
was published
for
org.apache.james:javax-mail-extension
(Maven)
Apr 3, 2023
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
High
CVE-2022-40308
was published
for
org.apache.archiva:archiva-common
(Maven)
Nov 15, 2022
XWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same reference
High
CVE-2022-31167
was published
for
org.xwiki.platform:xwiki-platform-security
(Maven)
Sep 20, 2022
ProTip!
Advisories are also available from the
GraphQL API