Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15 advisories

Loading
Privilege Escalation Flaw in Elasticsearch Moderate
CVE-2020-7014 was published for org.elasticsearch:elasticsearch (Maven) Mar 18, 2021
Incorrect Privilege Assignment in RESTEasy High
CVE-2014-3490 was published for org.jboss.resteasy:resteasy-client (Maven) May 14, 2022
Jenkins allows for Privilege Escalation by Remote Authenticated Users Moderate
CVE-2015-1814 was published for org.jenkins-ci.main:jenkins-core (Maven) May 17, 2022
Jenkins allows for Privilege Escalation by Remote Authenticated Users Moderate
CVE-2015-1806 was published for org.jenkins-ci.main:jenkins-core (Maven) May 17, 2022
Incorrect Privilege Assignment in Jenkins Script Security Plugin High
CVE-2019-10355 was published for org.jenkins-ci.plugins:script-security (Maven) May 24, 2022
Improper Privilege Management in Elasticsearch High
CVE-2020-7009 was published for org.elasticsearch:elasticsearch (Maven) May 24, 2022
XWiki Platform allows remote code execution from user account Critical
CVE-2024-37899 was published for org.xwiki.platform:xwiki-platform-oldcore (Maven) Jun 20, 2024
XWiki allows privilege escalation through link refactoring High
CVE-2025-49580 was published for org.xwiki.platform:xwiki-platform-refactoring-default (Maven) Jun 13, 2025
manuelleduc Credited to manuelleduc
NutzBoot Incorrect Privilege Assignment vulnerability Moderate
CVE-2025-13806 was published for org.nutz:nutzboot-parent (Maven) Dec 1, 2025
Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes Low
CVE-2025-13881 was published for org.keycloak:keycloak-services (Maven) Feb 2, 2026
eminaktas Credited to eminaktas
Keycloak Affected by Broken Access Control Vulnerability in the UserManagedPermissionService Moderate
CVE-2025-14778 was published for org.keycloak:keycloak-services (Maven) Feb 9, 2026
eminaktas Credited to eminaktas
Keycloak: manage-clients permission escalates to full realm admin access Moderate
CVE-2026-3121 was published for org.keycloak:keycloak-services (Maven) Mar 26, 2026
Duplicate Advisory: Keycloak has privilege escalation via improper scope mapping enforcement High
GHSA-8hcx-p7m8-gc28 was published for org.keycloak:keycloak-services (Maven) May 28, 2026 withdrawn
Keycloak has privilege escalation via improper scope mapping enforcement High
CVE-2026-9795 was published for org.keycloak:keycloak-services (Maven) Jul 1, 2026
ProTip! Advisories are also available from the GraphQL API