Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

26 advisories

Loading
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards Moderate
CVE-2026-69190 was published for org.graylog2:graylog2-server (Maven) Sep 22, 2026
kah-ja Credited to kah-ja
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens Moderate
CVE-2026-55867 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
michaelddickenson Credited to michaelddickenson and sreelim sreelim sreelim
Sakai Profile Image Deletion has an IDOR Moderate
CVE-2026-54050 was published for org.sakaiproject.profile2:profile2-api (Maven) Aug 24, 2026
geo-chen Credited to geo-chen and ottenhoff ottenhoff ottenhoff
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center Moderate
CVE-2025-32781 was published for com.ctrip.framework.apollo:apollo (Maven) Jul 13, 2026
lesignals Credited to lesignals
Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter Moderate
CVE-2026-49099 was published for org.apache.camel:camel-salesforce (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter Moderate
CVE-2026-48206 was published for org.apache.camel:camel-jira (Maven) Jul 6, 2026
oscerd Credited to oscerd
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463) Moderate
CVE-2026-54683 was published for nl.nl-portal:documenten-api (Maven) Jun 18, 2026
Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise Moderate
CVE-2026-9087 was published for org.keycloak:keycloak-services (Maven) May 20, 2026
Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers Moderate
CVE-2026-4630 was published for org.keycloak:keycloak-services (Maven) May 19, 2026
coffeemakr Credited to coffeemakr
Keycloak: Information Disclosure via evaluate-scopes Admin API Moderate
CVE-2026-37978 was published for org.keycloak:keycloak-services (Maven) May 19, 2026
Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key Moderate
CVE-2025-62241 was published for com.liferay.commerce:com.liferay.commerce.order.content.web (Maven) Oct 13, 2025
Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key Moderate
CVE-2025-62242 was published for com.liferay:com.liferay.change.tracking.web (Maven) Oct 13, 2025
Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key Moderate
CVE-2025-62252 was published for com.liferay.portal:com.liferay.portal.impl (Maven) Oct 13, 2025
Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key Moderate
CVE-2025-62244 was published for com.liferay:com.liferay.change.tracking.web (Maven) Oct 13, 2025
Liferay Portal Vulnerable to IDOR via audit events Moderate
CVE-2025-43827 was published for com.liferay:com.liferay.portal.security.audit.storage.service (Maven) Sep 30, 2025
Liferay Portal and DXP allows users to add a note to a different virtual instance Moderate
CVE-2025-43810 was published for com.liferay.commerce:com.liferay.commerce.service (Maven) Sep 23, 2025
Liferay Contacts Center widget has insecure direct object reference Moderate
CVE-2025-43803 was published for com.liferay:com.liferay.contacts.web (Maven) Sep 19, 2025
Liferay Portal API Allows Authenticated Users to Access Workflow Definitions by Name Moderate
CVE-2025-43782 was published for com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl (Maven) Sep 11, 2025
Liferay Portal Vulnerable to Insecure Direct Object Reference Moderate
CVE-2025-43732 was published for com.liferay:com.liferay.roles.selector.web (Maven) Aug 18, 2025
Spring Framework has Authorization Bypass for Case Sensitive Comparisons Moderate
CVE-2024-38827 was published for org.springframework.security:spring-security-core (Maven) Dec 2, 2024
bclozel Credited to bclozel
The OpenSearch reporting plugin improperly controls tenancy access to reporting resources Moderate
CVE-2024-39900 was published for org.opensearch.plugin:opensearch-reports-scheduler (Maven) Jul 18, 2024
Bonitasoft Runtime Community edition's contains an insecure direct object references vulnerability Moderate
CVE-2024-28087 was published for org.bonitasoft.engine:bonita-server (Maven) May 15, 2024
Authorization Bypass in Liferay Portal Moderate
CVE-2022-42129 was published for com.liferay.portal:release.portal.bom (Maven) Nov 15, 2022
Jenkins Google Compute Engine Plugin does not verify SSH host keys when connecting agents created by the plugin Moderate
CVE-2019-16546 was published for org.jenkins-ci.plugins:google-compute-engine (Maven) May 24, 2022
ProTip! Advisories are also available from the GraphQL API