GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,782 advisories
Filter by severity
OpenSearch unauthorized data access on fields protected by field level security if field is a member of an object
Moderate
GHSA-2rjv-cv85-xhgm
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Aug 1, 2025
OpenSearch unauthorized data access on fields protected by field masking for fields of type ip, geo_point, geo_shape, xy_point, xy_shape
Moderate
GHSA-rrmm-wq7q-h4v5
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Aug 1, 2025
Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability in the Image Plugin
Moderate
CVE-2025-24854
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jul 31, 2025
Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability via Header Link Rendering
Moderate
CVE-2025-24853
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jul 31, 2025
Apache Struts Extras Before 2 has an Improper Output Neutralization for Logs Vulnerability
Moderate
CVE-2025-54656
was published
for
org.apache.struts:struts-extras
(Maven)
Jul 30, 2025
Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
Moderate
CVE-2025-7784
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
Duplicate Advisory: Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
Moderate
GHSA-83j7-mhw9-388w
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 18, 2025
•
withdrawn
Keycloak phishing attack via email verification step in first login flow
Moderate
CVE-2025-7365
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
Duplicate Advisory: Keycloak phishing attack via email verification step in first login flow
Moderate
GHSA-gj52-35xm-gxjh
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 10, 2025
•
withdrawn
Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers
Moderate
CVE-2021-29038
was published
for
com.liferay.commerce:com.liferay.commerce.account.web
(Maven)
Feb 21, 2024
Liferay Portal and Liferay DXP User Enumeration Vulnerability
Moderate
CVE-2024-26268
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions
Moderate
CVE-2024-26267
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Two Forward Slashes
Moderate
CVE-2024-25609
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
Moderate
CVE-2024-25608
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Allows Templates to be Viewed via the UI or API
Moderate
CVE-2024-25605
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
Moderate
CVE-2024-25604
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel
Moderate
CVE-2024-25150
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options
Moderate
CVE-2024-25149
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Vulnerable to Open Redirect via Adaptive Media Administration Page
Moderate
CVE-2023-44308
was published
for
com.liferay:com.liferay.adaptive.media.web
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Vulnerable to Open Redirect in Countries Management's Edit Region Page
Moderate
CVE-2023-5190
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Keycloak vulnerable to two factor authentication bypass
Moderate
CVE-2025-3910
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 30, 2025
Opencast still publishes global system account credentials
Moderate
CVE-2025-54380
was published
for
org.opencastproject:opencast-common
(Maven)
Jul 25, 2025
Bouncy Castle Denial of Service (DoS)
Moderate
CVE-2023-33202
was published
for
org.bouncycastle:bcpkix-jdk18on
(Maven)
Nov 23, 2023
PowerJob vulnerable to Incorrect Access Control via the create user/save interface.
Moderate
CVE-2023-29922
was published
for
tech.powerjob:powerjob
(Maven)
Apr 19, 2023
pubnub Insufficient Entropy vulnerability
Moderate
CVE-2023-26154
was published
for
Pubnub
(RubyGems)
Dec 6, 2023
ProTip!
Advisories are also available from the
GraphQL API