GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
3,066 advisories
Filter by severity
Keycloak Affected by Broken Access Control Vulnerability in the UserManagedPermissionService
Moderate
CVE-2025-14778
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 9, 2026
Apache Avro Java SDK is Vulnerable to Code Injection
Moderate
CVE-2025-33042
was published
for
org.apache.avro:avro
(Maven)
Feb 13, 2026
Keycloak services allows the issuance of access and refresh tokens for disabled users
Moderate
CVE-2025-14559
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
XWiki vulnerable to click-jacking through CSS injection in comments
Moderate
CVE-2026-26000
was published
for
org.xwiki.platform:xwiki-platform-web
(Maven)
Feb 12, 2026
Apache Shiro has an Authentication Bypass
Moderate
CVE-2026-23903
was published
for
org.apache.shiro:shiro-spring
(Maven)
Feb 9, 2026
Keycloak logs sensitive headers
Moderate
CVE-2025-11537
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Feb 10, 2026
ThingsBoard vulnerable to stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature
Moderate
CVE-2025-34281
was published
for
org.thingsboard:application
(Maven)
Oct 17, 2025
Duplicate Advisory: Wildfly HAL Console Cross-Site Scripting
Moderate
GHSA-5wjw-h8x5-v65m
was published
for
org.jboss.hal:hal-console
(Maven)
Jan 14, 2025
•
withdrawn
Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion
Moderate
CVE-2025-14969
was published
for
org.hibernate.reactive:hibernate-reactive-core
(Maven)
Jan 26, 2026
Neo4j Enterprise and Community vulnerable to a potential information disclosure
Moderate
CVE-2026-1622
was published
for
org.neo4j:neo4j
(Maven)
Feb 4, 2026
Apache Syncope: Reflected XSS on Enduser Login
Moderate
CVE-2026-23794
was published
for
org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui
(Maven)
Feb 3, 2026
Apache Syncope: Console XXE on Keymaster parameters
Moderate
CVE-2026-23795
was published
for
org.apache.syncope.client.idrepo:syncope-client-idrepo-console
(Maven)
Feb 3, 2026
Stored Cross-site Scripting in folder-auth plugin
Moderate
CVE-2022-27200
was published
for
io.jenkins.plugins:folder-auth
(Maven)
Mar 18, 2022
Duplicate Advisory: Stored Cross-site Scripting vulnerability in Jenkins Folder-based Authorization Strategy Plugin
Moderate
GHSA-chr6-386q-4m3v
was published
for
io.jenkins.plugins:folder-auth
(Maven)
Mar 16, 2022
•
withdrawn
Crafter CMS has Improper Control of Dynamically-Managed Code Resources
Moderate
CVE-2026-1770
was published
for
org.craftercms:craftercms
(Maven)
Feb 2, 2026
Eclipse Dataspace Components's ConsumerPullTransferTokenValidationApiController doesn't check for token validit
Moderate
CVE-2024-8642
was published
for
org.eclipse.edc:transfer-data-plane
(Maven)
Sep 11, 2024
Duplicate Advisory: WildFly Elytron OpenID Connect Client Extension authorization code injection attack
Moderate
GHSA-4v5x-9m47-cqr2
was published
for
org.wildfly:wildfly-elytron-oidc-client-subsystem
(Maven)
Dec 9, 2024
•
withdrawn
weixin4j has Improperly Controlled Sequential Memory Allocation
Moderate
CVE-2026-24819
was published
for
com.foxinmy:weixin4j-base
(Maven)
Jan 27, 2026
Quick-Media Batik Codec FIX Package has Buffer Overflow Vulnerability in PNG Codec
Moderate
CVE-2026-24807
was published
for
com.github.liuyueyi.media:batik-codec-fix
(Maven)
Jan 27, 2026
Quick-Media Batik Codec FIX package has Code Injection vulnerability
Moderate
CVE-2026-24806
was published
for
com.github.liuyueyi.media:batik-codec-fix
(Maven)
Jan 27, 2026
jsonrpc4j has Infinite Loop in RPC Stream Writer
Moderate
CVE-2026-24802
was published
for
com.github.briandilley.jsonrpc4j:jsonrpc4j
(Maven)
Jan 27, 2026
XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages
Moderate
CVE-2026-24128
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Jan 23, 2026
Timing Attack Vulnerability in SCRAM Authentication
Moderate
CVE-2025-59432
was published
for
com.ongres.scram:scram-common
(Maven)
Sep 16, 2025
Apache CXF: Untrusted JMS configuration can lead to RCE
Moderate
CVE-2025-48913
was published
for
org.apache.cxf:cxf-rt-transports-jms
(Maven)
Aug 8, 2025
Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide
Moderate
CVE-2025-22234
was published
for
org.springframework.security:spring-security-core
(Maven)
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API