Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

111 advisories

Loading
Jeecg boot arbitrary file read vulnerability High
CVE-2023-41578 was published for org.jeecgframework.boot:jeecg-boot-parent (Maven) Sep 8, 2023
pf4j vulnerable to remote code execution via the zippluginPath parameter High
CVE-2023-40826 was published for org.pf4j:pf4j (Maven) Aug 29, 2023
pf4j vulnerable to remote code execution via expandIfZip method in the extract function High
CVE-2023-40828 was published for org.pf4j:pf4j (Maven) Aug 29, 2023
pf4j vulnerable to remote code execution via loadpluginPath parameter High
CVE-2023-40827 was published for org.pf4j:pf4j (Maven) Aug 29, 2023
Arbitrary File Creation in AbstractUnArchiver High
CVE-2023-37460 was published for org.codehaus.plexus:plexus-archiver (Maven) Jul 25, 2023
uriyay-jfrog
Administration Console authentication bypass in openfire xmppserver High
CVE-2023-32315 was published for org.igniterealtime.openfire:xmppserver (Maven) May 23, 2023
akrherz Fishbowler
guusdk Siebene
HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057 High
CVE-2023-28465 was published for ca.uhn.hapi.fhir:org.hl7.fhir.convertors (Maven) Mar 10, 2023
JLLeitschuh
org.neo4j.procedure:apoc Path Traversal Vulnerability High
CVE-2022-23532 was published for org.neo4j.procedure:apoc (Maven) Jan 13, 2023
Gravitee API Management contains Path Traversal High
CVE-2022-38723 was published for io.gravitee.apim:gravitee-api-management (Maven) Jan 4, 2023
Path Traversal In MeterSpere leads to upload file to any path High
CVE-2022-46178 was published for io.metersphere:metersphere (Maven) Dec 30, 2022
Widoco Path Traversal vulnerability High
CVE-2022-4772 was published for com.github.dgarijo:Widoco (Maven) Dec 28, 2022
Apache Atlas: zip path traversal in import functionality High
CVE-2022-34271 was published for org.apache.atlas:apache-atlas (Maven) Dec 14, 2022
FusionAuth vulnerable to directory traversal attack High
CVE-2022-45921 was published for io.fusionauth:fusionauth-java-client (Maven) Nov 28, 2022
TestNG is vulnerable to Path Traversal High
CVE-2022-4065 was published for org.testng:testng (Maven) Nov 19, 2022
cosmotron ljacomet
mayerrobert
Jenkins Config Rotator Plugin vulnerable to path traversal High
CVE-2022-45388 was published for org.jenkins-ci.main:config-rotator (Maven) Nov 16, 2022
NotMyFault
Arbitrary file read vulnerability in Jenkins Pipeline Utility Steps Plugin High
CVE-2022-45381 was published for org.jenkins-ci.plugins:pipeline-utility-steps (Maven) Nov 16, 2022
NotMyFault
Path Traversal in Liferay Portal High
CVE-2022-42125 was published for com.liferay.portal:release.portal.bom (Maven) Nov 15, 2022
Path Traversal in Liferay Portal High
CVE-2022-42123 was published for com.liferay.portal:release.portal.bom (Maven) Nov 15, 2022
Apache Ivy vulnerable to path traversal High
CVE-2022-37866 was published for org.apache.ivy:ivy (Maven) Nov 7, 2022
Apache UIMA Path Traversal vulnerability High
CVE-2022-32287 was published for org.apache.uima:uimaj-core (Maven) Nov 3, 2022
Goomph before 3.37.2 allows malicious zip file to write contents to arbitrary locations High
CVE-2022-26049 was published for com.diffplug.gradle:goomph (Maven) Sep 12, 2022
Path Traversal in Payara High
CVE-2022-37422 was published for fish.payara.api:payara-bom (Maven) Aug 19, 2022
DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import High
CVE-2022-31195 was published for org.dspace:dspace-api (Maven) Aug 6, 2022
JSPUI vulnerable to path traversal in submission (resumable) upload High
CVE-2022-31194 was published for org.dspace:dspace-jspui (Maven) Aug 6, 2022
Arbitrary file write vulnerability in Jenkins CLIF Performance Testing plugin High
CVE-2022-36894 was published for org.jenkins-ci.plugins:clif-performance-testing (Maven) Jul 28, 2022
NotMyFault
ProTip! Advisories are also available from the GraphQL API