GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,411
Erlang
33
GitHub Actions
22
Go
2,146
Maven
5,000+
npm
3,808
NuGet
687
pip
3,481
Pub
12
RubyGems
897
Rust
899
Swift
38
Unreviewed advisories
All unreviewed
5,000+
69 advisories
Filter by severity
xwiki-platform-web-templates allows users to be created even when registration is disabled without validation via template macro
Moderate
CVE-2023-29513
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 20, 2023
PowerJob vulnerable to Incorrect Access Control via the create user/save interface.
Moderate
CVE-2023-29922
was published
for
tech.powerjob:powerjob
(Maven)
Apr 19, 2023
Jenkins OctoPerf Load Testing Plugin missing permission check allows for ID enumeration
Moderate
CVE-2023-28673
was published
for
org.jenkinsci.plugins:octoperf
(Maven)
Apr 2, 2023
Jenkins OctoPerf Load Testing Plugin missing permission check allows for unauthorized server connections
Moderate
CVE-2023-28675
was published
for
org.jenkinsci.plugins:octoperf
(Maven)
Apr 2, 2023
XWiki Platform users may execute anything with superadmin right through comments and async macro
Critical
CVE-2023-26471
was published
for
org.xwiki.platform:xwiki-platform-rendering-async-macro
(Maven)
Mar 3, 2023
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
Critical
CVE-2023-26474
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Mar 3, 2023
Unprivileged XWiki Platform users can make arbitrary select queries using DatabaseListProperty and suggest.vm
Moderate
CVE-2023-26473
was published
for
org.xwiki.platform:xwiki-platform-web
(Maven)
Mar 3, 2023
Arbitrary code execution in de.tum.in.ase:artemis-java-test-sandbox
High
GHSA-98hq-4wmw-98w9
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Feb 10, 2023
Keycloak has lack of validation of access token on client registrations endpoint
Moderate
CVE-2023-0091
was published
for
org.keycloak:keycloak-core
(Maven)
Jan 12, 2023
Missing permission check in Jenkins Build Failure Analyzer Plugin
Moderate
CVE-2019-16554
was published
for
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
(Maven)
May 24, 2022
Wildfly Authorization Misconfiguration
Moderate
CVE-2019-14838
was published
for
org.wildfly.core:wildfly-host-controller
(Maven)
May 24, 2022
Improper Access Control in JBoss mod_cluster
Moderate
CVE-2012-1154
was published
for
org.jboss.mod_cluster:mod_cluster
(Maven)
May 17, 2022
Apache Struts2 Broken Access Control Vulnerability
Moderate
CVE-2013-4310
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Improper Access Control in Apache Hadoop
High
CVE-2016-5393
was published
for
org.apache.hadoop:hadoop-common
(Maven)
May 17, 2022
Elasticsearch Improper Access Control vulnerability
Moderate
CVE-2014-3120
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 17, 2022
Apache Ambari Improper Access Control
Critical
CVE-2016-6807
was published
for
org.apache.ambari:ambari
(Maven)
May 17, 2022
Apache Tomcat does not follow ServletSecurity annotations
Moderate
CVE-2011-1419
was published
for
org.apache.tomcat:tomcat
(Maven)
May 17, 2022
Path Traversal in Apache Atlas
High
CVE-2016-8752
was published
for
org.apache.atlas:atlas-common
(Maven)
May 17, 2022
Improper Access Control in Apache Tomcat
Moderate
CVE-2012-5885
was published
for
org.apache.tomcat:tomcat
(Maven)
May 17, 2022
Improper Access Control in Apache Derby
High
CVE-2010-2232
was published
for
org.apache.derby:derby
(Maven)
May 17, 2022
Improper Access Control in MySQL Connectors Java
Moderate
CVE-2015-2575
was published
for
mysql:mysql-connector-java
(Maven)
May 17, 2022
Improper Access Control in Apache WSS4J
Moderate
CVE-2015-0227
was published
for
org.apache.ws.security:wss4j
(Maven)
May 14, 2022
Improper Access Control in Elasticsearch
High
CVE-2015-1427
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 14, 2022
Improper Access Control in Elasticsearch
High
CVE-2015-4165
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 14, 2022
Improper Access Control in Apache Shiro
Critical
CVE-2016-4437
was published
for
org.apache.shiro:shiro-core
(Maven)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API