GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
37 advisories
Filter by severity
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
GHSA-p279-2cqp-84jg
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
Moderate
CVE-2025-32781
was published
for
com.ctrip.framework.apollo:apollo
(Maven)
Jul 13, 2026
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
High
CVE-2026-49464
was published
for
nl.nl-portal:taak
(Maven)
Jul 8, 2026
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
High
CVE-2026-54641
was published
for
io.openremote:openremote-manager
(Maven)
Jul 6, 2026
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
Critical
CVE-2026-57168
was published
for
io.openremote:openremote-manager
(Maven)
Jun 19, 2026
Keycloak Protection API allows authenticated clients to access and modify resources owned by other Resource Servers
Moderate
CVE-2026-4630
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise
Moderate
CVE-2026-9087
was published
for
org.keycloak:keycloak-services
(Maven)
May 20, 2026
OpenAM Arbitrary OAuth Token Minting via Push Registration
High
CVE-2026-46498
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jun 25, 2026
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
Moderate
CVE-2026-54683
was published
for
nl.nl-portal:documenten-api
(Maven)
Jun 18, 2026
Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
High
CVE-2026-40981
was published
for
org.springframework.cloud:spring-cloud-config-server
(Maven)
May 7, 2026
Keycloak: Information Disclosure via evaluate-scopes Admin API
Moderate
CVE-2026-37978
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
xxl-job Jobs Handler remove function allows improper control of resource identifiers via ID parameter
Low
CVE-2025-9264
was published
for
com.xuxueli:xxl-job-admin
(Maven)
Aug 21, 2025
xxl-job Vulnerable to Resource Injection and Authorization Bypass Through User-Controlled Key
Low
CVE-2025-9263
was published
for
com.xuxueli:xxl-job-admin
(Maven)
Aug 21, 2025
Keycloak vulnerable to authorization bypass via the Admin API
Low
CVE-2026-2366
was published
for
@keycloak/keycloak-admin-client
(Maven)
Mar 12, 2026
Liferay Portal Vulnerable to Insecure Direct Object Reference
Moderate
CVE-2025-43732
was published
for
com.liferay:com.liferay.roles.selector.web
(Maven)
Aug 18, 2025
Liferay Portal API Allows Authenticated Users to Access Workflow Definitions by Name
Moderate
CVE-2025-43782
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl
(Maven)
Sep 11, 2025
Liferay Portal is vulnerable to Insecure Direct Object Reference (IDOR) attack through Authentication Bypass
High
CVE-2025-43790
was published
for
com.liferay:com.liferay.object.service
(Maven)
Sep 11, 2025
Liferay Portal Vulnerable to IDOR via audit events
Moderate
CVE-2025-43827
was published
for
com.liferay:com.liferay.portal.security.audit.storage.service
(Maven)
Sep 30, 2025
Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62241
was published
for
com.liferay.commerce:com.liferay.commerce.order.content.web
(Maven)
Oct 13, 2025
Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62252
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 13, 2025
Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62242
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62244
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Portal and DXP allows users to add a note to a different virtual instance
Moderate
CVE-2025-43810
was published
for
com.liferay.commerce:com.liferay.commerce.service
(Maven)
Sep 23, 2025
Liferay Contacts Center widget has insecure direct object reference
Moderate
CVE-2025-43803
was published
for
com.liferay:com.liferay.contacts.web
(Maven)
Sep 19, 2025
Apache Ranger allows users to bypass intended access restrictions via direct access to module URLs
High
CVE-2015-0266
was published
for
org.apache.ranger:ranger
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API