GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,489
Maven
5,000+
npm
4,105
NuGet
735
pip
3,927
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
799 advisories
Filter by severity
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via Friendly URL Module
Critical
CVE-2022-42122
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Fragment Module
Critical
CVE-2022-42120
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
XWiki configuration files can be accessed through jsx and sx endpoints
Critical
CVE-2025-55748
was published
for
org.xwiki.platform:xwiki-platform-skin-skinx
(Maven)
Sep 3, 2025
XWiki configuration files can be accessed through the webjars API
Critical
CVE-2025-55747
was published
for
org.xwiki.platform:xwiki-platform-webjars-api
(Maven)
Sep 3, 2025
Valtimo scripting engine can be used to gain access to sensitive data or resources
Critical
CVE-2025-58059
was published
for
com.ritense.valtimo:core
(Maven)
Aug 28, 2025
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Critical
CVE-2025-54988
was published
for
org.apache.tika:tika-parser-pdf-module
(Maven)
Aug 20, 2025
Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions
Critical
CVE-2024-38002
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Vulnerable to XSS in the Fragment Components
Critical
CVE-2023-44309
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 17, 2023
Liferay Portal and Liferay DXP Vulnerable to Stored XSS in the Manage Vocabulary Page
Critical
CVE-2023-42629
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 17, 2023
Liferay Portal and Liferay DXP Vulnerable to Reflected XSS via the Export for Translation Page
Critical
CVE-2023-42497
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 17, 2023
Liferay Portal Allows RCE via Deserialization of a JSON Payload
Critical
CVE-2019-16891
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2022
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Critical
CVE-2025-24813
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Mar 10, 2025
Apache Tomcat - Authentication Bypass
Critical
CVE-2024-52316
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Nov 18, 2024
Remote code injection in Log4j
Critical
GHSA-94g7-hpv8-h9qm
was published
for
com.splunk.logging:splunk-library-javalogging
(Maven)
Dec 14, 2021
Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console
Critical
CVE-2024-8980
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Vulnerable to XSS in the Commerce Module
Critical
CVE-2023-42627
was published
for
com.liferay.commerce:com.liferay.commerce.address.content.web
(Maven)
Oct 17, 2023
Liferay Portal and Liferay DXP Vulnerable to XSS in the Wiki Widget
Critical
CVE-2023-42628
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 17, 2023
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
Critical
CVE-2025-32429
was published
for
org.xwiki.platform:xwiki-platform-distribution-war
(Maven)
Jul 24, 2025
Jeecg-boot vulnerable to SQL Injection
Critical
CVE-2022-45206
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via updateNullByEmptyString
Critical
CVE-2022-45207
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
PowerJob vulnerable to incorrect access control
Critical
CVE-2023-29924
was published
for
tech.powerjob:powerjob
(Maven)
Apr 21, 2023
Withdrawn Advisory: Improper Restriction of XML External Entity Reference in Apache ActiveMQ
Critical
CVE-2015-3208
was published
for
org.apache.activemq:activemq-client
(Maven)
May 14, 2022
•
withdrawn
Apache Struts file upload logic is flawed
Critical
CVE-2024-53677
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 11, 2024
Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
Critical
CVE-2024-29868
was published
for
org.apache.streampipes:streampipes-resource-management
(Maven)
Jun 24, 2024
Liferay Portal and Liferay DXP Vulnerable to XSS via the Page Tree Menu
Critical
CVE-2023-44310
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 17, 2023
ProTip!
Advisories are also available from the
GraphQL API