GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            2,990 advisories
        Filter by severity
        
      
      
    
                    
                      HTTP request smuggling in netty
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-43797
                      
                      was published
                        for
                        
                          io.netty:netty
                        
                        (Maven)
                      Dec 9, 2021 
                    
                  
                    
                      Apache JSPWiki Cross-site Scripting due to carefully crafted plugin link invocation
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-40369
                      
                      was published
                        for
                        
                          org.apache.jspwiki:jspwiki-main
                        
                        (Maven)
                      Dec 2, 2021 
                    
                  
                    
                      Deserialization of Untrusted Data in Spring AMQP
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-22095
                      
                      was published
                        for
                        
                          org.springframework.amqp:spring-amqp
                        
                        (Maven)
                      Dec 1, 2021 
                    
                  
                    
                      Improper certificate management in AWS IoT Device SDK v2
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-40828
                      
                      was published
                        for
                        
                          aws-iot-device-sdk-v2
                        
                        (Maven)
                      Nov 24, 2021 
                    
                  
                    
                      Apache Ozone exposes OM, SCM and Datanode metadata
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-41532
                      
                      was published
                        for
                        
                          org.apache.ozone:ozone-main
                        
                        (Maven)
                      Nov 23, 2021 
                    
                  
                    
                      Incorrect permissions in Apache Ozone
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-39235
                      
                      was published
                        for
                        
                          org.apache.ozone:ozone-main
                        
                        (Maven)
                      Nov 23, 2021 
                    
                  
                    
                      Incorrect Authorization in Apache Ozone
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-39234
                      
                      was published
                        for
                        
                          org.apache.ozone:ozone-main
                        
                        (Maven)
                      Nov 23, 2021 
                    
                  
                    
                      Request injection in Spring Cloud Gateway
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-22051
                      
                      was published
                        for
                        
                          org.springframework.cloud:spring-cloud-gateway
                        
                        (Maven)
                      Nov 10, 2021 
                    
                  
                    
                      Reflected cross-site scripting in vaadin-menu-bar webjar resources in Vaadin 14
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-33611
                      
                      was published
                        for
                        
                          com.vaadin:vaadin-bom
                        
                        (Maven)
                      Nov 3, 2021 
                    
                  
                    
                      Infinite loop in Apache MINA
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-41973
                      
                      was published
                        for
                        
                          org.apache.mina:mina-core
                        
                        (Maven)
                      Nov 3, 2021 
                    
                  
                    
                      XSS in `*Text` options of the Datepicker widget in jquery-ui
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-41183
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Oct 26, 2021 
                    
                  
                    
                      XSS in the `of` option of the `.position()` util in jquery-ui
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-41184
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Oct 26, 2021 
                    
                  
                    
                      XSS in the `altField` option of the Datepicker widget in jquery-ui
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-41182
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Oct 26, 2021 
                    
                  
                    
                      Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-19
                    
                      
  Moderate
                    
                
                      
                        GHSA-fr26-qjc8-mvjx
                      
                      was published
                        for
                        
                          com.vaadin:flow-server
                        
                        (Maven)
                      Oct 13, 2021 
                    
                  
                    
                      Denial of service in DataCommunicator class in Vaadin 8
                    
                      
  Moderate
                    
                
                      
                        GHSA-j23j-q57m-63v3
                      
                      was published
                        for
                        
                          com.vaadin:vaadin-server
                        
                        (Maven)
                      Oct 13, 2021 
                    
                  
                    
                      Denial of service in DataCommunicator class in Vaadin 8
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-33609
                      
                      was published
                        for
                        
                          com.vaadin:vaadin-server
                        
                        (Maven)
                      Oct 13, 2021 
                    
                  
                    
                      Code injection in Kubernetes Java Client
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-25738
                      
                      was published
                        for
                        
                          io.kubernetes:client-java
                        
                        (Maven)
                      Oct 12, 2021 
                    
                  
                    
                      XML External Entity Reference in org.opencms:opencms-core
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-3312
                      
                      was published
                        for
                        
                          org.opencms:opencms-core
                        
                        (Maven)
                      Oct 12, 2021 
                    
                  
                    
                      Cross-site Scripting in XXL-JOB
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-29204
                      
                      was published
                        for
                        
                          com.xuxueli:xxl-job-core
                        
                        (Maven)
                      Oct 12, 2021 
                    
                  
                    
                      Improper Input Validation in Jakarta Expression Language
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-28170
                      
                      was published
                        for
                        
                          com.sun.el:el-ri
                        
                        (Maven)
                      Oct 6, 2021 
                    
                  
                    
                      Cross-site Scripting in OpenCRX
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-25959
                      
                      was published
                        for
                        
                          org.opencrx:opencrx-client
                        
                        (Maven)
                      Sep 30, 2021 
                    
                  
                    
                      Druid ingestion system Authenticated users can read data from other sources than intended 
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-36749
                      
                      was published
                        for
                        
                          org.apache.druid:druid-core
                        
                        (Maven)
                      Sep 27, 2021 
                    
                  
                    
                      Observable Discrepancy in Apache Kafka
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-38153
                      
                      was published
                        for
                        
                          org.apache.kafka:kafka-clients
                        
                        (Maven)
                      Sep 23, 2021 
                    
                  
                    
                      Exposure of Sensitive Information in keycloak
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-1744
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-core
                        
                        (Maven)
                      Sep 20, 2021 
                    
                  
                    
                      Exposure of sensitive information in Elasticsearch
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-22147
                      
                      was published
                        for
                        
                          org.elasticsearch:elasticsearch
                        
                        (Maven)
                      Sep 20, 2021 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API