GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,231
Erlang
31
GitHub Actions
20
Go
1,991
Maven
5,000+
npm
3,709
NuGet
661
pip
3,341
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,759 advisories
Filter by severity
Open Redirect in Liferay Portal
High
CVE-2020-24554
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 7, 2021
Server-Side Request Forgery in Spinnaker Orca
High
CVE-2020-9298
was published
for
com.netflix.spinnaker.orca:orca-core
(Maven)
May 7, 2021
Authentication bypass in Apache Shiro
High
CVE-2020-13933
was published
for
org.apache.shiro:shiro-core
(Maven)
May 7, 2021
Exposure of Sensitive Information to an Unauthorized Actor in Apache Wicket
High
CVE-2020-11976
was published
for
org.apache.wicket:wicket-core
(Maven)
May 7, 2021
trentm/json vulnerable to command injection
High
CVE-2020-7712
was published
for
json
(Maven)
May 6, 2021
Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19
High
CVE-2021-31411
was published
for
com.vaadin:vaadin-bom
(Maven)
May 6, 2021
Regular expression Denial of Service (ReDoS) in EmailValidator class in V7 compatibility module in Vaadin 8
High
CVE-2021-31409
was published
for
com.vaadin:vaadin-compatibility-server
(Maven)
May 4, 2021
Improper Authentication in Apache Hadoop
High
CVE-2018-11765
was published
for
org.apache.hadoop:hadoop-main
(Maven)
Apr 30, 2021
Allocation of Resources Without Limits or Throttling in Undertow
High
CVE-2020-10705
was published
for
io.undertow:undertow-core
(Maven)
Apr 30, 2021
Logic error in Legion of the Bouncy Castle BC Java
High
CVE-2020-28052
was published
for
org.bouncycastle:bcprov-ext-jdk15on
(Maven)
Apr 30, 2021
Authentication bypass for specific endpoint
High
CVE-2021-29442
was published
for
com.alibaba.nacos:nacos-common
(Maven)
Apr 27, 2021
Authentication Bypass
High
CVE-2021-29441
was published
for
com.alibaba.nacos:nacos-common
(Maven)
Apr 27, 2021
Cross-Site Request Forgery in Vert.x-Web framework
High
CVE-2020-35217
was published
for
io.vertx:vertx-web
(Maven)
Apr 22, 2021
"Deserialization errors in MyBatis"
High
CVE-2020-26945
was published
for
org.mybatis:mybatis
(Maven)
Apr 22, 2021
Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17
High
GHSA-crh4-294p-vcfq
was published
for
com.vaadin:vaadin-text-field-flow
(Maven)
Apr 19, 2021
OSGi applications using Vaadin 12-14 and 19 vulnerable to server classes and resources exposure
High
CVE-2021-31407
was published
for
com.vaadin:flow-server
(Maven)
Apr 19, 2021
Regular expression denial of service (ReDoS) in EmailValidator class in Vaadin 7
High
CVE-2020-36320
was published
for
com.vaadin:vaadin-bom
(Maven)
Apr 19, 2021
Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17
High
CVE-2021-31405
was published
for
com.vaadin:vaadin-bom
(Maven)
Apr 19, 2021
Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19
High
GHSA-j9wr-49vq-rm5g
was published
for
com.vaadin:vaadin-bom
(Maven)
Apr 19, 2021
Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources
High
CVE-2021-28165
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Apr 6, 2021
Rating Script Service expose XWiki to SQL injection
High
CVE-2021-21380
was published
for
org.xwiki.platform:xwiki-platform-ratings-api
(Maven)
Mar 23, 2021
XStream can cause a Denial of Service.
High
CVE-2021-21341
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Mar 22, 2021
Potential remote code execution in Apache Tomcat
High
CVE-2021-25329
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Mar 19, 2021
Uncontrolled Resource Consumption in Apache Thrift
High
CVE-2020-13949
was published
for
org.apache.thrift:libthrift
(Maven)
Mar 12, 2021
Sensitive information disclosure via log in com.bmuschko:gradle-vagrant-plugin
High
CVE-2021-21361
was published
for
com.bmuschko:gradle-vagrant-plugin
(Maven)
Mar 9, 2021
ProTip!
Advisories are also available from the
GraphQL API