GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
Improper Input Validation in Jakarta Expression Language
Moderate
CVE-2021-28170
was published
for
com.sun.el:el-ri
(Maven)
Oct 6, 2021
Apache Tiles Vulnerable to XSS via EL Expression Injection
Moderate
CVE-2009-1275
was published
for
org.apache.tiles:tiles-core
(Maven)
May 2, 2022
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat...
Moderate
Unreviewed
CVE-2010-1871
was published
May 17, 2022
An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11,...
Moderate
Unreviewed
CVE-2019-11628
was published
May 24, 2022
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and...
Moderate
Unreviewed
CVE-2020-3956
was published
May 24, 2022
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 ...
Moderate
Unreviewed
CVE-2022-34466
was published
Jul 13, 2022
TYPO3 CMS vulnerable to Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
Moderate
CVE-2022-23504
was published
for
typo3/cms
(Composer)
Dec 13, 2022
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
Moderate
CVE-2023-20861
was published
for
org.springframework:spring-expression
(Maven)
Mar 23, 2023
Arbitrary javascript injection in Apache Jena
Moderate
CVE-2023-22665
was published
for
org.apache.jena:jena
(Maven)
Apr 25, 2023
A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by...
Moderate
Unreviewed
CVE-2024-7552
was published
Aug 6, 2024
A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be...
Moderate
Unreviewed
CVE-2024-9672
was published
Dec 10, 2024
QOS.CH logback-core Expression Language Injection vulnerability
Moderate
CVE-2024-12798
was published
for
ch.qos.logback:logback-core
(Maven)
Dec 19, 2024
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression...
Moderate
Unreviewed
CVE-2026-31380
was published
May 19, 2026
Caddy CVE-2026-30852 Fix Bypass
Moderate
GHSA-wwhq-w58m-w29c
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 19, 2026
A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is...
Moderate
Unreviewed
CVE-2026-41719
was published
Jun 10, 2026
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious...
Moderate
Unreviewed
CVE-2026-40985
was published
Jun 11, 2026
Improper neutralization of special elements used in an expression language statement ('expression...
Moderate
Unreviewed
CVE-2026-11561
was published
Jun 11, 2026
ProTip!
Advisories are also available from the
GraphQL API