GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
26 advisories
Filter by severity
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
Moderate
CVE-2026-69190
was published
for
org.graylog2:graylog2-server
(Maven)
Sep 22, 2026
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
Moderate
CVE-2026-55867
was published
for
org.graylog2:graylog2-server
(Maven)
Aug 28, 2026
Sakai Profile Image Deletion has an IDOR
Moderate
CVE-2026-54050
was published
for
org.sakaiproject.profile2:profile2-api
(Maven)
Aug 24, 2026
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
Moderate
CVE-2025-32781
was published
for
com.ctrip.framework.apollo:apollo
(Maven)
Jul 13, 2026
Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter
Moderate
CVE-2026-49099
was published
for
org.apache.camel:camel-salesforce
(Maven)
Jul 6, 2026
Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter
Moderate
CVE-2026-48206
was published
for
org.apache.camel:camel-jira
(Maven)
Jul 6, 2026
Apache Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation
Moderate
CVE-2026-46453
was published
for
org.apache.camel:camel-elasticsearch-rest-client
(Maven)
Jul 6, 2026
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
Moderate
CVE-2026-54683
was published
for
nl.nl-portal:documenten-api
(Maven)
Jun 18, 2026
Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise
Moderate
CVE-2026-9087
was published
for
org.keycloak:keycloak-services
(Maven)
May 20, 2026
Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers
Moderate
CVE-2026-4630
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
Keycloak: Information Disclosure via evaluate-scopes Admin API
Moderate
CVE-2026-37978
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62241
was published
for
com.liferay.commerce:com.liferay.commerce.order.content.web
(Maven)
Oct 13, 2025
Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62242
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62252
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 13, 2025
Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62244
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Portal Vulnerable to IDOR via audit events
Moderate
CVE-2025-43827
was published
for
com.liferay:com.liferay.portal.security.audit.storage.service
(Maven)
Sep 30, 2025
Liferay Portal and DXP allows users to add a note to a different virtual instance
Moderate
CVE-2025-43810
was published
for
com.liferay.commerce:com.liferay.commerce.service
(Maven)
Sep 23, 2025
Liferay Contacts Center widget has insecure direct object reference
Moderate
CVE-2025-43803
was published
for
com.liferay:com.liferay.contacts.web
(Maven)
Sep 19, 2025
Liferay Portal API Allows Authenticated Users to Access Workflow Definitions by Name
Moderate
CVE-2025-43782
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl
(Maven)
Sep 11, 2025
Liferay Portal Vulnerable to Insecure Direct Object Reference
Moderate
CVE-2025-43732
was published
for
com.liferay:com.liferay.roles.selector.web
(Maven)
Aug 18, 2025
Spring Framework has Authorization Bypass for Case Sensitive Comparisons
Moderate
CVE-2024-38827
was published
for
org.springframework.security:spring-security-core
(Maven)
Dec 2, 2024
The OpenSearch reporting plugin improperly controls tenancy access to reporting resources
Moderate
CVE-2024-39900
was published
for
org.opensearch.plugin:opensearch-reports-scheduler
(Maven)
Jul 18, 2024
Bonitasoft Runtime Community edition's contains an insecure direct object references vulnerability
Moderate
CVE-2024-28087
was published
for
org.bonitasoft.engine:bonita-server
(Maven)
May 15, 2024
Authorization Bypass in Liferay Portal
Moderate
CVE-2022-42129
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Jenkins Google Compute Engine Plugin does not verify SSH host keys when connecting agents created by the plugin
Moderate
CVE-2019-16546
was published
for
org.jenkins-ci.plugins:google-compute-engine
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API