GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,848
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
49 advisories
Filter by severity
Liferay Portal and Liferay DXP Allows Templates to be Viewed via the UI or API
Moderate
CVE-2024-25605
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled
Moderate
CVE-2022-41414
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 7, 2022
Liferay Portal and Liferay DXP has incorrect default permissions for site members
Moderate
CVE-2021-38268
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Mar 3, 2022
Liferay Portal and Liferay DXP fails to check permissions to view sites/groups
Moderate
CVE-2022-26595
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Apr 20, 2022
Liferay Portal and Liferay DXP does not properly check user permission
Moderate
CVE-2021-33327
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissions
Moderate
CVE-2021-33333
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Don't Check Permissions of Pages
Moderate
CVE-2021-33324
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Improper Preservation of Permissions in xxl-job
High
CVE-2024-42681
was published
for
com.xuxueli:xxl-job-core
(Maven)
Aug 15, 2024
Liferay Portal and Liferay DXP Fails to Properly Check User Permissions
Moderate
CVE-2021-33334
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Liferay Portal and Liferay DXP Fails to Check Permissions
Moderate
CVE-2021-29052
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Incorrect Default Permissions in Liferay Portal
Moderate
CVE-2022-42130
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Incorrect Default Permissions in Liferay Portal
Moderate
CVE-2022-42127
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Cache confusion in Jenkins Eiffel Broadcaster Plugin
Moderate
CVE-2025-24400
was published
for
com.axis.jenkins.plugins.eiffel:eiffel-broadcaster
(Maven)
Jan 22, 2025
Improper handling of case sensitivity in Jenkins OpenId Connect Authentication Plugin
High
CVE-2025-24399
was published
for
org.jenkins-ci.plugins:oic-auth
(Maven)
Jan 22, 2025
RuoYi has insecure permissions
Moderate
CVE-2024-57438
was published
for
com.ruoyi:ruoyi
(Maven)
Jan 29, 2025
Snowflake JDBC uses insecure temporary credential cache file permissions
Moderate
CVE-2025-24790
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Jan 29, 2025
Incorrect Default Permissions in Apache DolphinScheduler
High
CVE-2020-13922
was published
for
org.apache.dolphinscheduler:dolphinscheduler-api
(Maven)
Feb 9, 2022
Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
High
CVE-2024-52551
was published
for
org.jenkinsci.plugins:pipeline-model-parent
(Maven)
Nov 13, 2024
Duplicate Advisory: Apiman has insufficient checks for read permissions
High
GHSA-54r5-wr8x-x5v3
was published
for
io.apiman:apiman-manager-api-rest-impl
(Maven)
Dec 20, 2022
•
withdrawn
Duplicate Advisory: Keycloak: Leak of configured LDAP bind credentials
Low
GHSA-gmrm-8fx4-66x7
was published
for
org.keycloak:keycloak-core
(Maven)
Jun 18, 2024
•
withdrawn
Incorrect Default Permissions in Apache Tomcat
High
CVE-2020-8022
was published
for
org.apache.tomcat:tomcat
(Maven)
Feb 9, 2022
•
withdrawn
Keycloak leaks configured LDAP bind credentials through the Keycloak admin console
Low
CVE-2024-5967
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Jun 21, 2024
Apache Tomcat may be started without proper security settings
High
CVE-2002-0493
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 30, 2022
CSRF vulnerability in Jenkins Coverity Plugin allow capturing credentials
Moderate
CVE-2023-23848
was published
for
org.jenkins-ci.plugins:synopsys-coverity
(Maven)
Feb 15, 2023
Jenkins Build Step Plugin fails to check Item/Build permission
Moderate
CVE-2017-1000089
was published
for
org.jenkins-ci.plugins:pipeline-build-step
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API