GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
2,482 advisories
Filter by severity
WildFly improper RBAC permission
Moderate
CVE-2025-23367
was published
for
org.wildfly.core:wildfly-server
(Maven)
Jan 31, 2025
Duplicate Advisory: Wildfly Server Role Based Access Control (RBAC) provider has Improper Access Control
Moderate
GHSA-fcrw-mphx-7cxf
was published
for
org.wildfly:wildfly-server
(Maven)
Jan 30, 2025
•
withdrawn
Snowflake JDBC uses insecure temporary credential cache file permissions
Moderate
CVE-2025-24790
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Jan 29, 2025
RuoYi vulnerable to Denial of Service by attackers with admin privileges
Moderate
CVE-2024-57439
was published
for
com.ruoyi:ruoyi
(Maven)
Jan 29, 2025
RuoYi has insecure permissions
Moderate
CVE-2024-57438
was published
for
com.ruoyi:ruoyi
(Maven)
Jan 29, 2025
Apache Hive Incorrectly Assigns Permissions for a Critical Resource
Moderate
CVE-2024-29869
was published
for
org.apache.hive:hive-exec
(Maven)
Jan 29, 2025
Apache Hive vulnerable to Observable Timing Discrepancy and Authentication Bypass by Spoofing
Moderate
CVE-2024-23953
was published
for
org.apache.hive:hive-llap-common
(Maven)
Jan 28, 2025
Infinispan vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-0736
was published
for
org.infinispan:infinispan-parent
(Maven)
Jan 28, 2025
Apache Solr Relative Path Traversal vulnerability
Moderate
CVE-2024-52012
was published
for
org.apache.solr:solr-core
(Maven)
Jan 27, 2025
HL7 FHIR IG Publisher potentially exposes GitHub repo user and credential information
Moderate
CVE-2025-24363
was published
for
org.hl7.fhir.publisher:org.hl7.fhir.publisher.cli
(Maven)
Jan 24, 2025
Cross site scripting in Silverpeas Core
Moderate
CVE-2024-56923
was published
for
org.silverpeas.core:silverpeas-core
(Maven)
Jan 22, 2025
CSRF vulnerability in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24402
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
Disabled permissions can be granted by Folder-based in Jenkins Authorization Strategy Plugin
Moderate
CVE-2025-24401
was published
for
io.jenkins.plugins:folder-auth
(Maven)
Jan 22, 2025
Missing permission checks in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24403
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
Incorrect permission check in Jenkins GitLab Plugin allows enumerating credentials IDs
Moderate
CVE-2025-24397
was published
for
org.jenkins-ci.plugins:gitlab-plugin
(Maven)
Jan 22, 2025
Cache confusion in Jenkins Eiffel Broadcaster Plugin
Moderate
CVE-2025-24400
was published
for
com.axis.jenkins.plugins.eiffel:eiffel-broadcaster
(Maven)
Jan 22, 2025
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
CVE-2025-0604
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Jan 22, 2025
Elasticsearch allocation of resources without limits or throttling leads to crash
Moderate
CVE-2024-43709
was published
for
org.elasticsearch:elasticsearch
(Maven)
Jan 21, 2025
Apache CXF: Denial of Service vulnerability with temporary files
Moderate
CVE-2025-23184
was published
for
org.apache.cxf:cxf-core
(Maven)
Jan 21, 2025
HAL Console has a Cross Site Scripting (XSS) vulnerability of user input
Moderate
CVE-2025-23366
was published
for
org.jboss.hal:hal-console
(Maven)
Jan 16, 2025
Insecure Temporary File in RESTEasy
Moderate
CVE-2023-0482
was published
for
org.jboss.resteasy:resteasy-core
(Maven)
Jan 15, 2025
Duplicate Advisory: Wildfly HAL Console Cross-Site Scripting
Moderate
GHSA-5wjw-h8x5-v65m
was published
for
org.jboss.hal:hal-console
(Maven)
Jan 14, 2025
•
withdrawn
Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability
Moderate
CVE-2024-45627
was published
for
org.apache.linkis:linkis-metadata-query-service-jdbc
(Maven)
Jan 14, 2025
Denial of Service in Keycloak Server via Security Headers
Moderate
CVE-2024-11734
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Jan 13, 2025
Keycloak allows unrestricted admin use of system and environment variables
Moderate
CVE-2024-11736
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Jan 13, 2025
ProTip!
Advisories are also available from the
GraphQL API