GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
163 advisories
Filter by severity
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
Spring Security annotation detection mechanism has authorization bypass
High
CVE-2025-41248
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 16, 2025
Liferay Portal JSON Web Services Direct Class Invocation Enables Service Access Policy Execution
Low
CVE-2025-43789
was published
for
com.liferay:com.liferay.comment.web
(Maven)
Sep 12, 2025
Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data
Moderate
CVE-2025-43784
was published
for
com.liferay:com.liferay.headless.builder.impl
(Maven)
Sep 10, 2025
Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions
Critical
CVE-2024-38002
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
Moderate
CVE-2024-25604
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options
Moderate
CVE-2024-25149
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
XWiki Rendering is vulnerable to RCE attacks when processing nested macros
Critical
CVE-2025-53836
was published
for
org.xwiki.rendering:xwiki-rendering-transformation-macro
(Maven)
Jul 14, 2025
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
Low
CVE-2025-27427
was published
for
org.apache.activemq:artemis-server
(Maven)
Apr 1, 2025
Improper Authentication vulnerability in Apache Solr
Critical
CVE-2024-45216
was published
for
org.apache.solr:solr
(Maven)
Oct 16, 2024
Sandbox bypass vulnerability in Script Security Plugin
High
CVE-2020-2135
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 24, 2022
XWiki allows remote code execution through preview of XClass changes in AWM editor
High
CVE-2025-49586
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 13, 2025
WSO2 products vulnerable to privilege escalation due to business logic flaw in SOAP admin services
Moderate
CVE-2024-7096
was published
for
org.wso2.am:am-parent
(Maven)
May 30, 2025
Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users
High
CVE-2025-48881
was published
for
com.ritense.valtimo:object-management
(Maven)
May 28, 2025
Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers
High
CVE-2021-33335
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Tokens stored in plain text by PaaSLane Estimate Plugin
Moderate
CVE-2023-50777
was published
for
com.cloudtp.jenkins:paaslane-estimate
(Maven)
Dec 13, 2023
XWiki uses the wrong wiki reference in AuthorizationManager
High
CVE-2025-29924
was published
for
org.xwiki.platform:xwiki-platform-security-authorization-api
(Maven)
Mar 19, 2025
XWiki allows remote code execution through the extension sheet
Critical
CVE-2024-55662
was published
for
org.xwiki.platform:xwiki-platform-repository-server-ui
(Maven)
Dec 12, 2024
Solr script service doesn't take dropped programming right into account
Low
CVE-2025-32971
was published
for
org.xwiki.platform:xwiki-platform-search-solr-api
(Maven)
Apr 29, 2025
Apache Ranger allows users to bypass intended access restrictions via the REST API
Moderate
CVE-2015-5167
was published
for
org.apache.ranger:ranger
(Maven)
May 17, 2022
Apache Ranger allows users to bypass intended access restrictions via direct access to module URLs
High
CVE-2015-0266
was published
for
org.apache.ranger:ranger
(Maven)
May 17, 2022
Cache confusion in Jenkins Eiffel Broadcaster Plugin
Moderate
CVE-2025-24400
was published
for
com.axis.jenkins.plugins.eiffel:eiffel-broadcaster
(Maven)
Jan 22, 2025
Incorrect Authorization in Apache Solr
Critical
CVE-2020-13957
was published
for
org.apache.solr:solr-core
(Maven)
Feb 10, 2022
WSO2 incorrect authorization vulnerability
Moderate
CVE-2024-2321
was published
for
org.wso2.am:am-parent
(Maven)
Feb 27, 2025
Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions
Moderate
CVE-2025-24860
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 4, 2025
ProTip!
Advisories are also available from the
GraphQL API