GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,684
Maven
5,000+
npm
4,313
NuGet
760
pip
4,091
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,011 advisories
Filter by severity
Keycloak has debug default bind address
Moderate
CVE-2025-11538
was published
for
org.keycloak:keycloak-quarkus-dist
(Maven)
Dec 2, 2025
Duplicate Advisory: Keycloak allows Binding to an Unrestricted IP Address
Moderate
GHSA-7m9g-pmxf-m9m8
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 13, 2025
•
withdrawn
NutzBoot Incorrect Privilege Assignment vulnerability
Moderate
CVE-2025-13806
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
Duplicate Advisory: Discovery uses the same AES/GCM Nonce throughout the session
Moderate
GHSA-wp4m-7hpj-8qp8
was published
for
tech.pegasys.discovery:discovery
(Maven)
Jan 20, 2024
•
withdrawn
ThingsBoard allows an authenticated user to upload malicious SVG images
Moderate
CVE-2025-3261
was published
for
org.thingsboard:application
(Maven)
Nov 27, 2025
Keycloak does not invalidate sessions when "Remember Me" is disabled
Moderate
CVE-2025-11429
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 23, 2025
Keycloak does not invalidate offline sessions when the offline_access scope is removed
Moderate
CVE-2025-12110
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 23, 2025
Keycloak vulnerable to session takeovers due to reuse of session identifiers
Moderate
CVE-2025-12390
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 28, 2025
Eclipse JGit XML External Entity (XXE) Vulnerability
Moderate
CVE-2025-4949
was published
for
org.eclipse.jgit:org.eclipse.jgit
(Maven)
May 21, 2025
GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML format
Moderate
CVE-2025-21621
was published
for
org.geoserver.web:gs-web-app
(Maven)
Nov 25, 2025
lsFusion Platform has a Path Traversal vulnerability
Moderate
CVE-2025-13262
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
lsFusion Platform has a Path Traversal vulnerability
Moderate
CVE-2025-13261
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
lsFusion Server is vulnerable to Path Traversal through its unpackFile function
Moderate
CVE-2025-13265
was published
for
lsfusion.platform:server
(Maven)
Nov 17, 2025
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Nov 25, 2025
XWiki view file macro: User can view content of office file without view rights on the attachment
Moderate
CVE-2025-65089
was published
for
com.xwiki.pro:xwiki-pro-macros-ui
(Maven)
Nov 18, 2025
Bootstrap Cross-site Scripting vulnerability
Moderate
CVE-2018-14041
was published
for
bootstrap
(RubyGems)
Sep 13, 2018
XWiki AdminTools application doesn't set permissions on the AdminTools space
Moderate
CVE-2025-54990
was published
for
com.xwiki.admintools:application-admintools
(Maven)
Nov 18, 2025
vlife-base has Path Traversal vulnerability
Moderate
CVE-2025-13266
was published
for
io.github.wwwlike:vlife-base
(Maven)
Nov 17, 2025
Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62241
was published
for
com.liferay.commerce:com.liferay.commerce.order.content.web
(Maven)
Oct 13, 2025
Liferay Portal Stores Password Reset Tokens in Plain Text
Moderate
CVE-2025-62261
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 28, 2025
Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature
Moderate
CVE-2025-62262
was published
for
com.liferay:com.liferay.portal.security.ldap.impl
(Maven)
Oct 27, 2025
Liferay Portal Vulnerable to Cross-Site Scripting
Moderate
CVE-2025-62263
was published
for
com.liferay:com.liferay.account.admin.web
(Maven)
Oct 27, 2025
Liferay Portal ComboServlet denial of service via large file combination
Moderate
CVE-2025-62254
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 24, 2025
Liferay Portal and DXP do not properly restrict access to OpenAPI
Moderate
CVE-2025-62256
was published
for
com.liferay:com.liferay.portal.security.auth.verifier
(Maven)
Oct 23, 2025
Liferay Portal and DXP do not check permissions of images in a blog entry
Moderate
CVE-2025-62275
was published
for
com.liferay:com.liferay.blogs.item.selector.web
(Maven)
Nov 1, 2025
ProTip!
Advisories are also available from the
GraphQL API