GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
39 advisories
Filter by severity
When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server
High
CVE-2017-12615
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 17, 2018
Unrestricted Upload of File with Dangerous Type in mingsoft:ms-mcms
Critical
CVE-2018-18830
was published
for
net.mingsoft:ms-mcms
(Maven)
Nov 1, 2018
Unrestricted upload of file with dangerous type in Apache Solr
Critical
CVE-2019-12409
was published
for
org.apache.solr:solr-core
(Maven)
Jan 28, 2020
XStream is vulnerable to an Arbitrary Code Execution attack
Moderate
CVE-2021-21344
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Mar 22, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
Moderate
CVE-2021-21346
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Mar 22, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
Moderate
CVE-2021-21347
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Mar 22, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
Moderate
CVE-2021-21350
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Mar 22, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
Moderate
CVE-2021-21351
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Mar 22, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39154
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39151
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
XStream is vulnerable to an Arbitrary Code Execution attack
High
CVE-2021-39149
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
Arbitrary file upload in Mingsoft MCMS
Critical
CVE-2022-23315
was published
for
net.mingsoft:ms-mcms
(Maven)
Jan 22, 2022
Arbitrary File Upload in Mingsoft MCMS
Critical
CVE-2022-22929
was published
for
net.mingsoft:ms-mcms
(Maven)
Jan 22, 2022
Mingsoft MCMS vulnerable to Remote Code Execution via file upload.
Critical
CVE-2021-46386
was published
for
net.mingsoft:ms-mcms
(Maven)
Jan 27, 2022
Unrestricted Upload of File with Dangerous Type in Liferay Portal and Liferay DXP
Moderate
CVE-2020-15839
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 10, 2022
File upload leading to RCE in MCMS
Critical
CVE-2021-46036
was published
for
net.mingsoft:ms-mcms
(Maven)
Feb 19, 2022
Unrestricted Upload of File with Dangerous Type in Apache Struts2
High
CVE-2012-1592
was published
for
org.apache.struts:struts2-core
(Maven)
Apr 23, 2022
Unrestricted Upload of File with Dangerous Type Apache Tomcat
High
CVE-2017-12617
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Input Validation in Apache ActiveMQ
Critical
CVE-2016-3088
was published
for
org.apache.activemq:activemq-client
(Maven)
May 14, 2022
Sandbox bypass vulnerability through implicitly allowlisted platform Groovy files in Jenkins Pipeline: Groovy Plugin
High
CVE-2022-30945
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
May 18, 2022
Unrestricted Upload of File with Dangerous Type in Sonatype Nexus Repository Manager
High
CVE-2019-16530
was published
for
org.sonatype.nexus:nexus-repository
(Maven)
May 24, 2022
Jeecg-Boot CMS arbitrary file upload vulnerability
Critical
CVE-2020-28088
was published
for
org.jeecgframework.boot:jeecg-boot-parent
(Maven)
May 24, 2022
JFinal file validation vulnerability
High
CVE-2019-17352
was published
for
com.jfinal:jfinal
(Maven)
May 25, 2022
Code injection in MCMS
Critical
CVE-2022-30506
was published
for
net.mingsoft:ms-mcms
(Maven)
Jun 3, 2022
Unrestricted Upload of File with Dangerous Type in MCMS
Critical
CVE-2022-31943
was published
for
net.mingsoft:ms-mcms
(Maven)
Jul 2, 2022
ProTip!
Advisories are also available from the
GraphQL API