GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            31 advisories
        Filter by severity
        
      
      
    
                    
                      Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
                    
                      
  Critical
                    
                
                      
                        CVE-2024-23897
                      
                      was published
                        for
                        
                          org.jenkins-ci.main:jenkins-core
                        
                        (Maven)
                      Jan 24, 2024 
                    
                  
                    
                      Deep Java Library path traversal issue
                    
                      
  Critical
                    
                
                      
                        CVE-2025-0851
                      
                      was published
                        for
                        
                          ai.djl:api
                        
                        (Maven)
                      Jan 29, 2025 
                    
                  
                    
                      Path traversal in Hadoop
                    
                      
  Critical
                    
                
                      
                        CVE-2022-26612
                      
                      was published
                        for
                        
                          org.apache.hadoop:hadoop-common
                        
                        (Maven)
                      Apr 8, 2022 
                    
                  
                    
                      Apache Struts file upload logic is flawed
                    
                      
  Critical
                    
                
                      
                        CVE-2024-53677
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-core
                        
                        (Maven)
                      Dec 11, 2024 
                    
                  
                    
                      Apache Ivy does not verify target path when extracting the archive
                    
                      
  Critical
                    
                
                      
                        CVE-2022-37865
                      
                      was published
                        for
                        
                          org.apache.ivy:ivy
                        
                        (Maven)
                      Nov 7, 2022 
                    
                  
                    
                      Path Traversal in Apache Shiro
                    
                      
  Critical
                    
                
                      
                        CVE-2023-34478
                      
                      was published
                        for
                        
                          org.apache.shiro:shiro-web
                        
                        (Maven)
                      Jul 24, 2023 
                    
                  
                    
                      Apache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification
                    
                      
  Critical
                    
                
                      
                        CVE-2024-27317
                      
                      was published
                        for
                        
                          org.apache.pulsar:pulsar-functions-worker
                        
                        (Maven)
                      Mar 12, 2024 
                    
                  
                    
                      Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
                    
                      
  Critical
                    
                
                      
                        CVE-2024-47883
                      
                      was published
                        for
                        
                          org.openrefine.dependencies:butterfly
                        
                        (Maven)
                      Oct 24, 2024 
                    
                  
                    
                      Apache Linkis Zip Slip issue
                    
                      
  Critical
                    
                
                      
                        CVE-2023-27603
                      
                      was published
                        for
                        
                          org.apache.linkis:linkis
                        
                        (Maven)
                      Jul 6, 2023 
                    
                  
                    
                      Apache StreamPark Path Traversal vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2022-45802
                      
                      was published
                        for
                        
                          org.apache.streampark:streampark-common_2.11
                        
                        (Maven)
                      Jul 6, 2023 
                    
                  
                    
                      CometVisu Backend for openHAB affected by RCE through path traversal
                    
                      
  Critical
                    
                
                      
                        CVE-2024-42469
                      
                      was published
                        for
                        
                          org.openhab.ui.bundles:org.openhab.ui.cometvisu
                        
                        (Maven)
                      Aug 9, 2024 
                    
                  
                    
                      Remote code execution in Spring Cloud Data Flow
                    
                      
  Critical
                    
                
                      
                        CVE-2024-37084
                      
                      was published
                        for
                        
                          org.springframework.cloud:spring-cloud-skipper
                        
                        (Maven)
                      Jul 25, 2024 
                    
                  
                    
                      DeepJavaLibrary API absolute path traversal
                    
                      
  Critical
                    
                
                      
                        CVE-2024-37902
                      
                      was published
                        for
                        
                          ai.djl:api
                        
                        (Maven)
                      Jun 17, 2024 
                    
                  
                    
                      Genie Path Traversal vulnerability via File Uploads
                    
                      
  Critical
                    
                
                      
                        CVE-2024-4701
                      
                      was published
                        for
                        
                          com.netflix.genie:genie-web
                        
                        (Maven)
                      May 9, 2024 
                    
                  
                    
                      Path Traversal in Apache Struts
                    
                      
  Critical
                    
                
                      
                        CVE-2016-6795
                      
                      was published
                        for
                        
                          org.apache.struts:struts2-convention-plugin
                        
                        (Maven)
                      May 14, 2022 
                    
                  
                    
                      Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
                    
                      
  Critical
                    
                
                      
                        CVE-2021-21692
                      
                      was published
                        for
                        
                          org.jenkins-ci.main:jenkins-core
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
                    
                      
  Critical
                    
                
                      
                        CVE-2021-21686
                      
                      was published
                        for
                        
                          org.jenkins-ci.main:jenkins-core
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
                    
                      
  Critical
                    
                
                      
                        CVE-2021-21690
                      
                      was published
                        for
                        
                          org.jenkins-ci.main:jenkins-core
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Yamcs API Directory Traversal vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2023-45278
                      
                      was published
                        for
                        
                          org.yamcs:yamcs
                        
                        (Maven)
                      Oct 19, 2023 
                    
                  
                    
                      org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converter
                    
                      
  Critical
                    
                
                      
                        CVE-2023-37913
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-office-importer
                        
                        (Maven)
                      Oct 25, 2023 
                    
                  
                    
                      Remote code execution in UReport
                    
                      
  Critical
                    
                
                      
                        CVE-2020-21125
                      
                      was published
                        for
                        
                          com.bstek.ureport:ureport2-core
                        
                        (Maven)
                      Sep 20, 2021 
                    
                  
                    
                      Eclipse Vert.x does not properly neutralize '' (forward slashes) sequences that can resolve to an external location
                    
                      
  Critical
                    
                
                      
                        CVE-2018-12542
                      
                      was published
                        for
                        
                          io.vertx:vertx-web
                        
                        (Maven)
                      Oct 17, 2018 
                    
                  
                    
                       MITM based Zip Slip in `ca.uhn.hapi.fhir:org.hl7.fhir.core`
                    
                      
  Critical
                    
                
                      
                        CVE-2023-24057
                      
                      was published
                        for
                        
                          ca.uhn.hapi.fhir:org.hl7.fhir.convertors
                        
                        (Maven)
                      Jan 23, 2023 
                    
                  
                    
                      Arbitrary file deletion in ureport
                    
                      
  Critical
                    
                
                      
                        CVE-2023-24188
                      
                      was published
                        for
                        
                          com.bstek.ureport:ureport2-core
                        
                        (Maven)
                      Feb 13, 2023 
                    
                  
                    
                      Path traversal in Apache James
                    
                      
  Critical
                    
                
                      
                        CVE-2021-40525
                      
                      was published
                        for
                        
                          org.apache.james:james-server
                        
                        (Maven)
                      Jan 21, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API