GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,047
Maven
5,000+
npm
3,739
NuGet
668
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
103 advisories
Filter by severity
Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
Critical
CVE-2022-22963
was published
for
org.springframework.cloud:spring-cloud-function-context
(Maven)
Apr 3, 2022
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 ...
Moderate
Unreviewed
CVE-2022-34466
was published
Jul 13, 2022
Improper Input Validation in GeoServer
High
CVE-2022-24847
was published
for
org.geoserver:gs-main
(Maven)
Apr 22, 2022
Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the...
Critical
Unreviewed
CVE-2023-27821
was published
Mar 28, 2023
Liima before 1.17.28 allows server-side template injection.
Critical
Unreviewed
CVE-2023-26092
was published
Feb 20, 2023
Improper Input Validation in Jakarta Expression Language
Moderate
CVE-2021-28170
was published
for
com.sun.el:el-ri
(Maven)
Oct 6, 2021
Expression Language Injection in Apache Syncope
Critical
CVE-2020-1959
was published
for
org.apache.syncope:syncope-core
(Maven)
Jun 16, 2021
Expression Language Injection in Netflix Conductor
Critical
CVE-2020-9296
was published
for
com.netflix.conductor:conductor-core
(Maven)
Feb 10, 2022
Remote code execution in Apache Struts
Critical
CVE-2020-17530
was published
for
org.apache.struts:struts2-core
(Maven)
Feb 9, 2022
Remote Code Execution in SCIMono
High
CVE-2021-21479
was published
for
com.sap.scimono:scimono-server
(Maven)
Feb 10, 2021
Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and...
Critical
Unreviewed
CVE-2019-5916
was published
May 13, 2022
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
High
Unreviewed
CVE-2018-16621
was published
May 13, 2022
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the...
High
Unreviewed
CVE-2019-9041
was published
May 13, 2022
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access...
High
Unreviewed
CVE-2021-32834
was published
May 24, 2022
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList...
High
Unreviewed
CVE-2020-26565
was published
May 24, 2022
A tvxlanlegend expression language injection remote code execution vulnerability was discovered...
High
Unreviewed
CVE-2020-7185
was published
May 24, 2022
A reportpage index expression language injection remote code execution vulnerability was...
High
Unreviewed
CVE-2020-7187
was published
May 24, 2022
A userselectpagingcontent expression language injection remote code execution vulnerability was...
High
Unreviewed
CVE-2020-7188
was published
May 24, 2022
A forwardredirect expression language injection remote code execution vulnerability was...
High
Unreviewed
CVE-2020-7183
was published
May 24, 2022
A devgroupselect expression language injection remote code execution vulnerability was discovered...
Critical
Unreviewed
CVE-2020-7146
was published
May 24, 2022
A operatorgroupselectcontent expression language injection remote code execution vulnerability...
Critical
Unreviewed
CVE-2020-7162
was published
May 24, 2022
A syslogtempletselectwin expression language injection remote code execution vulnerability was...
Critical
Unreviewed
CVE-2020-24651
was published
May 24, 2022
A addvsiinterfaceinfo expression language injection remote code execution vulnerability was...
Critical
Unreviewed
CVE-2020-24652
was published
May 24, 2022
A adddevicetoview expression language injection remote code execution vulnerability was...
Critical
Unreviewed
CVE-2020-7141
was published
May 24, 2022
A operationselect expression language injection remote code execution vulnerability was...
Critical
Unreviewed
CVE-2020-7164
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API