GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
57 advisories
Filter by severity
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
High
CVE-2026-55771
was published
for
com.cedarpolicy:cedar-java
(Maven)
Jul 28, 2026
CedarJava has policy injection vulnerability
High
CVE-2026-55773
was published
for
com.cedarpolicy:cedar-java
(Maven)
Jun 19, 2026
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
High
CVE-2026-49832
was published
for
org.dspace:dspace-api
(Maven)
Jul 8, 2026
Apache Flink: Remote code execution via SQL injection in code generation
High
CVE-2026-35194
was published
for
org.apache.flink:flink-table-api-java
(Maven)
May 15, 2026
Apache Atlas has a Code Injection Vulnerability
High
CVE-2026-40563
was published
for
org.apache.atlas:apache-atlas
(Maven)
May 4, 2026
Spring AI has a VectorStore FilterExpression Converter injection
High
CVE-2026-40967
was published
for
org.springframework.ai:spring-ai-vector-store
(Maven)
Apr 28, 2026
jdbi3-freemarker Vulnerable to Improper Neutralization of Special Elements Used in FreeMarker Template Engine
High
GHSA-mggx-p7jf-jgw4
was published
for
org.jdbi:jdbi3-freemarker
(Maven)
May 5, 2026
Apache ActiveMQ Vulnerable to Improper Input Validation and Code Injection
High
CVE-2026-40466
was published
for
org.apache.activemq:activemq-all
(Maven)
Apr 24, 2026
Arbitrary File Read Vulnerability in Apache Dolphinscheduler
High
CVE-2023-51770
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Feb 20, 2024
Apache Ambari: authenticated users could perform command injection to perform RCE
High
CVE-2023-50379
was published
for
org.apache.ambari.contrib.views:ambari-contrib-views
(Maven)
Feb 27, 2024
c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
High
CVE-2026-27830
was published
for
com.mchange:c3p0
(Maven)
Feb 25, 2026
Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox
High
GHSA-c4pg-5ggh-vcpp
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Jan 19, 2024
•
withdrawn
XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injection
High
CVE-2025-66474
was published
for
org.xwiki.rendering:xwiki-rendering-xml
(Maven)
Dec 10, 2025
OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed
High
CVE-2025-64099
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Nov 12, 2025
XStream is vulnerable to a Remote Command Execution attack
High
CVE-2021-39144
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
Improper Input Validation in Apache Solr
High
CVE-2019-17558
was published
for
org.apache.solr:solr-core
(Maven)
Feb 12, 2020
XML External Entity (XXE) Injection in Apache Solr
High
CVE-2019-0193
was published
for
org.apache.solr:solr-core
(Maven)
Aug 1, 2019
H2O Vulnerable to Denial of Service (DoS) and File Write
High
CVE-2024-10572
was published
for
ai.h2o:h2o-ext-xgboost
(Maven)
Mar 20, 2025
Code injection in Apache Ant
High
CVE-2020-11979
was published
for
org.apache.ant:ant
(Maven)
Feb 3, 2021
XWiki Blog Application: Privilege Escalation (PR) from account through blog content
High
CVE-2025-58365
was published
for
org.xwiki.contrib.blog:application-blog-ui
(Maven)
Sep 8, 2025
Remote Code Execution vulnerability in Apache IoTDB via UDF
High
CVE-2023-46226
was published
for
apache-iotdb
(Maven)
Jan 15, 2024
XWiki allows remote code execution through default value of wiki macro wiki-type parameters
High
CVE-2025-49581
was published
for
org.xwiki.platform:xwiki-platform-rendering-wikimacro-store
(Maven)
Jun 13, 2025
XStream is vulnerable to a Remote Command Execution attack
High
CVE-2021-29505
was published
for
com.thoughtworks.xstream:xstream
(Maven)
May 18, 2021
Jenkins Templating Engine Plugin Vulnerable to Arbitrary Code Execution
High
CVE-2025-31722
was published
for
org.jenkins-ci.plugins:templating-engine
(Maven)
Apr 2, 2025
Apache StreamPark: FreeMarker SSTI RCE Vulnerability
High
CVE-2024-29178
was published
for
org.apache.streampark:streampark
(Maven)
Jul 18, 2024
ProTip!
Advisories are also available from the
GraphQL API