GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,993 advisories
Filter by severity
Jenkins has a log message injection vulnerability
Moderate
CVE-2025-59476
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 17, 2025
Liferay search widget vulnerable to Cross-site Scripting
Moderate
CVE-2025-43804
was published
for
com.liferay:com.liferay.portal.search
(Maven)
Sep 17, 2025
Liferay Portal allows remote attackers to view display page templates via crafted URLs
Moderate
CVE-2025-43805
was published
for
com.liferay:com.liferay.asset.display.page.service
(Maven)
Sep 17, 2025
Timing Attack Vulnerability in SCRAM Authentication
Moderate
CVE-2025-59432
was published
for
com.ongres.scram:scram-common
(Maven)
Sep 16, 2025
Liferay Portal has unchecked input for loop condition vulnerability in XML-RPC
Moderate
CVE-2025-43801
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 16, 2025
Openfire has potential identity spoofing issue via unsafe CN parsing
Moderate
CVE-2025-59154
was published
for
org.igniterealtime.openfire:xmppserver
(Maven)
Sep 16, 2025
Liferay Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-43802
was published
for
com.liferay.workspace:com.liferay.ticket.workspace
(Maven)
Sep 16, 2025
Liferay has Insecure Default Initialization of Resource issue
Moderate
CVE-2025-43797
was published
for
com.liferay:com.liferay.site.admin.web
(Maven)
Sep 16, 2025
Liferay Portal Uses Default Password
Moderate
CVE-2025-43799
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 15, 2025
Liferay Portal Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2025-43800
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
(Maven)
Sep 15, 2025
Liferay Portal vulnerable to Cross-site Scripting
Moderate
CVE-2025-43791
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
(Maven)
Sep 15, 2025
Liferay Portal has Improper Validation of Specified Quantity in Input
Moderate
CVE-2025-43793
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 15, 2025
Apache Fory Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-59328
was published
for
org.apache.fory:fory-core
(Maven)
Sep 15, 2025
Liferay Portal has stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-43794
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 15, 2025
Liferay Portal's System, Instance and Site Settings are vulnerable to Open Redirect
Moderate
CVE-2025-43795
was published
for
com.liferay:com.liferay.configuration.admin.web
(Maven)
Sep 12, 2025
Liferay Portal's selection modal is vulnerable to XSS
Moderate
CVE-2025-43787
was published
for
com.liferay:com.liferay.users.admin.web
(Maven)
Sep 12, 2025
Liferay Portal's Organization Selector exposes organization data to remote authenticated users
Moderate
CVE-2025-43788
was published
for
com.liferay:com.liferay.organizations.item.selector.web
(Maven)
Sep 12, 2025
Liferay Portal API Allows Authenticated Users to Access Workflow Definitions by Name
Moderate
CVE-2025-43782
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl
(Maven)
Sep 11, 2025
Liferay Portal is vulnerable to Reflected XSS attack through get_editor path
Moderate
CVE-2025-43783
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Sep 10, 2025
Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data
Moderate
CVE-2025-43784
was published
for
com.liferay:com.liferay.headless.builder.impl
(Maven)
Sep 10, 2025
Liferay Portal and Liferay DXP vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-43785
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 10, 2025
Liferay Portal exposes ERC which can lead to exploit the time response attack
Moderate
CVE-2025-43786
was published
for
com.liferay:com.liferay.headless.admin.workflow.impl
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attacks via its remote app title field
Moderate
CVE-2025-43775
was published
for
com.liferay:com.liferay.client.extension.web
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through its search bar portlet
Moderate
CVE-2025-43781
was published
for
com.liferay:com.liferay.portal.search.web
(Maven)
Sep 9, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
Moderate
CVE-2025-43776
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API