GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,790
Erlang
36
GitHub Actions
29
Go
2,370
Maven
5,000+
npm
3,994
NuGet
720
pip
3,783
Pub
12
RubyGems
927
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
279 advisories
Filter by severity
sbt vulnerable to arbitrary file write via archive extraction (Zip Slip)
Low
CVE-2023-46122
was published
for
org.scala-sbt:io_2.12
(Maven)
Oct 24, 2023
Yamcs Path Traversal vulnerability
High
CVE-2023-45277
was published
for
org.yamcs:yamcs
(Maven)
Oct 19, 2023
Yamcs API Directory Traversal vulnerability
Critical
CVE-2023-45278
was published
for
org.yamcs:yamcs
(Maven)
Oct 19, 2023
plexus-codehaus vulnerable to directory traversal
High
CVE-2022-4244
was published
for
org.codehaus.plexus:plexus-utils
(Maven)
Sep 25, 2023
Jeecg boot arbitrary file read vulnerability
High
CVE-2023-41578
was published
for
org.jeecgframework.boot:jeecg-boot-parent
(Maven)
Sep 8, 2023
Path traversal in Jenkins Job Configuration History Plugin
Moderate
CVE-2023-41930
was published
for
org.jenkins-ci.plugins:jobConfigHistory
(Maven)
Sep 6, 2023
pf4j vulnerable to remote code execution via the zippluginPath parameter
High
CVE-2023-40826
was published
for
org.pf4j:pf4j
(Maven)
Aug 29, 2023
pf4j vulnerable to remote code execution via expandIfZip method in the extract function
High
CVE-2023-40828
was published
for
org.pf4j:pf4j
(Maven)
Aug 29, 2023
pf4j vulnerable to remote code execution via loadpluginPath parameter
High
CVE-2023-40827
was published
for
org.pf4j:pf4j
(Maven)
Aug 29, 2023
Arbitrary File Creation in AbstractUnArchiver
High
CVE-2023-37460
was published
for
org.codehaus.plexus:plexus-archiver
(Maven)
Jul 25, 2023
Path Traversal in Apache Shiro
Critical
CVE-2023-34478
was published
for
org.apache.shiro:shiro-web
(Maven)
Jul 24, 2023
OpenRefine vulnerable to zip slip in project import
Moderate
CVE-2023-37476
was published
for
org.openrefine:main
(Maven)
Jul 18, 2023
Jenkins MathWorks Polyspace Plugin vulnerable to arbitrary file read
Moderate
CVE-2023-37960
was published
for
com.mathworks.polyspace.jenkins:mathworks-polyspace
(Maven)
Jul 12, 2023
Apache MINA SSHD information disclosure vulnerability
Moderate
CVE-2023-35887
was published
for
org.apache.sshd:sshd-common
(Maven)
Jul 10, 2023
Graylog server has partial path traversal vulnerability in Support Bundle feature
Low
CVE-2023-41044
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
Apache StreamPark Path Traversal vulnerability
Critical
CVE-2022-45802
was published
for
org.apache.streampark:streampark-common_2.11
(Maven)
Jul 6, 2023
Apache Linkis Zip Slip issue
Critical
CVE-2023-27603
was published
for
org.apache.linkis:linkis
(Maven)
Jul 6, 2023
hawtio vulnerable to Path Traversal
Moderate
CVE-2023-33544
was published
for
io.hawt:project
(Maven)
Jun 1, 2023
Administration Console authentication bypass in openfire xmppserver
High
CVE-2023-32315
was published
for
org.igniterealtime.openfire:xmppserver
(Maven)
May 23, 2023
Jenkins Code Dx Plugin missing permission checks
Moderate
CVE-2023-2196
was published
for
org.jenkins-ci.plugins:codedx
(Maven)
May 16, 2023
Jenkins Sidebar Link Plugin vulnerable to Path Traversal
Moderate
CVE-2023-32985
was published
for
org.jenkins-ci.plugins:sidebar-link
(Maven)
May 16, 2023
HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057
High
CVE-2023-28465
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Mar 10, 2023
Arbitrary file deletion in ureport
Critical
CVE-2023-24188
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Feb 13, 2023
StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route
Moderate
CVE-2023-24815
was published
for
io.vertx:vertx-web
(Maven)
Feb 10, 2023
Path Traversal In Eclipse GlassFish
Moderate
CVE-2022-2712
was published
for
org.glassfish.main.web:web
(Maven)
Jan 27, 2023
ProTip!
Advisories are also available from the
GraphQL API