GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,007 advisories
Filter by severity
Keycloak does not invalidate offline sessions when the offline_access scope is removed
Moderate
CVE-2025-12110
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 23, 2025
Keycloak does not invalidate sessions when "Remember Me" is disabled
Moderate
CVE-2025-11429
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 23, 2025
Keycloak vulnerable to session takeovers due to reuse of session identifiers
Moderate
CVE-2025-12390
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 28, 2025
Eclipse JGit XML External Entity (XXE) Vulnerability
Moderate
CVE-2025-4949
was published
for
org.eclipse.jgit:org.eclipse.jgit
(Maven)
May 21, 2025
GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML format
Moderate
CVE-2025-21621
was published
for
org.geoserver.web:gs-web-app
(Maven)
Nov 25, 2025
lsFusion Platform has a Path Traversal vulnerability
Moderate
CVE-2025-13262
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
lsFusion Platform has a Path Traversal vulnerability
Moderate
CVE-2025-13261
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
lsFusion Server is vulnerable to Path Traversal through its unpackFile function
Moderate
CVE-2025-13265
was published
for
lsfusion.platform:server
(Maven)
Nov 17, 2025
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Nov 25, 2025
XWiki view file macro: User can view content of office file without view rights on the attachment
Moderate
CVE-2025-65089
was published
for
com.xwiki.pro:xwiki-pro-macros-ui
(Maven)
Nov 18, 2025
Bootstrap Cross-site Scripting vulnerability
Moderate
CVE-2018-14041
was published
for
bootstrap
(RubyGems)
Sep 13, 2018
XWiki AdminTools application doesn't set permissions on the AdminTools space
Moderate
CVE-2025-54990
was published
for
com.xwiki.admintools:application-admintools
(Maven)
Nov 18, 2025
vlife-base has Path Traversal vulnerability
Moderate
CVE-2025-13266
was published
for
io.github.wwwlike:vlife-base
(Maven)
Nov 17, 2025
Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62241
was published
for
com.liferay.commerce:com.liferay.commerce.order.content.web
(Maven)
Oct 13, 2025
Liferay Portal Stores Password Reset Tokens in Plain Text
Moderate
CVE-2025-62261
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 28, 2025
Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature
Moderate
CVE-2025-62262
was published
for
com.liferay:com.liferay.portal.security.ldap.impl
(Maven)
Oct 27, 2025
Liferay Portal Vulnerable to Cross-Site Scripting
Moderate
CVE-2025-62263
was published
for
com.liferay:com.liferay.account.admin.web
(Maven)
Oct 27, 2025
Liferay Portal ComboServlet denial of service via large file combination
Moderate
CVE-2025-62254
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 24, 2025
Liferay Portal and DXP do not properly restrict access to OpenAPI
Moderate
CVE-2025-62256
was published
for
com.liferay:com.liferay.portal.security.auth.verifier
(Maven)
Oct 23, 2025
Liferay Portal and DXP do not check permissions of images in a blog entry
Moderate
CVE-2025-62275
was published
for
com.liferay:com.liferay.blogs.item.selector.web
(Maven)
Nov 1, 2025
Liferay Portal and DXP use an incorrect cache-control header
Moderate
CVE-2025-62276
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Nov 1, 2025
Liferay Portal and DXP affected by multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page
Moderate
CVE-2025-62267
was published
for
com.liferay:com.liferay.dynamic.data.mapping.item.selector.web
(Maven)
Oct 31, 2025
Liferay Portal Vulnerable to Reflected XSS via the selectedLanguageId Parameter
Moderate
CVE-2025-62264
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 31, 2025
Apache Struts Extras Before 2 has an Improper Output Neutralization for Logs Vulnerability
Moderate
CVE-2025-54656
was published
for
org.apache.struts:struts-extras
(Maven)
Jul 30, 2025
Pekko Management may not properly apply authenticator when Basic Authentication is enabled
Moderate
CVE-2025-46548
was published
for
com.lightbend.akka.management:akka-management_2.12
(Maven)
Jun 3, 2025
ProTip!
Advisories are also available from the
GraphQL API