GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,849
Pub
12
RubyGems
941
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
10,350 advisories
Filter by severity
Bagist Cross-site Scripting vulnerability
Moderate
CVE-2024-27499
was published
for
bagisto/bagisto
(Composer)
Mar 1, 2024
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
Moderate
CVE-2025-4581
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Aug 9, 2025
The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
Moderate
CVE-2019-10219
was published
for
org.hibernate.validator:hibernate-validator
(Maven)
Jan 8, 2020
uptrace pgdriver SQL injection vulnerability
Moderate
CVE-2024-44906
was published
for
github.com/uptrace/bun/driver/pgdriver
(Go)
Jun 12, 2025
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
Moderate
CVE-2025-53864
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Jul 11, 2025
Regular Expression Denial of Service (ReDoS) in lodash
Moderate
CVE-2019-1010266
was published
for
lodash
(RubyGems)
Jul 19, 2019
Prototype Pollution in lodash
Moderate
CVE-2018-3721
was published
for
lodash
(RubyGems)
Jul 26, 2018
MantisBT may disclose project names to unauthorized users
Moderate
CVE-2023-44394
was published
for
mantisbt/mantisbt
(Composer)
Oct 17, 2023
Regular Expression Denial of Service (ReDoS) in lodash
Moderate
CVE-2020-28500
was published
for
lodash
(RubyGems)
Jan 6, 2022
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
Moderate
CVE-2025-55003
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
Moderate
CVE-2025-55001
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao TOTP Secrets Engine Code Reuse
Moderate
CVE-2025-55000
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao Userpass and LDAP User Lockout Bypass
Moderate
CVE-2025-54998
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
Craft CMS has a theoretical bypass for CVE-2025-23209
Moderate
CVE-2025-54417
was published
for
craftcms/cms
(Composer)
Aug 8, 2025
TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)
Moderate
CVE-2025-55149
was published
for
tiny-scientist
(pip)
Aug 11, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
CVE-2025-54368
was published
for
uv
(pip)
Aug 7, 2025
Liferay Portal and Liferay DXP Organization Selector Does Not Check User Permissions
Moderate
CVE-2023-3426
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Aug 2, 2023
Liferay Portal and Liferay DXP Vulnerable to XSS via the Layout Module
Moderate
CVE-2023-3193
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Jun 15, 2023
Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module
Moderate
CVE-2023-35029
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Jun 15, 2023
Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module
Moderate
CVE-2022-42119
was published
for
com.liferay.commerce:com.liferay.commerce.catalog.web
(Maven)
Nov 15, 2022
Liferay Portal and Liferay DXP Vulnerable to XSS via the Portal Search Module
Moderate
CVE-2022-42118
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Liferay Portal and Liferay DXP Vulnerable to XSS via the Announcements Module
Moderate
CVE-2022-42110
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Liferay Portal and Liferay DXP Vulnerable to XSS via the Sharing Module
Moderate
CVE-2022-42111
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Liferay Portal Vulnerable to XSS in Profile Search Functionality
Moderate
CVE-2016-3670
was published
for
com.liferay:com.liferay.portal.search.web
(Maven)
May 17, 2022
Liferay Portal Vulnerable to XSS via Mishandled Title or Summary in the Web Content Display
Moderate
CVE-2017-12649
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API