Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

54 advisories

Loading
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets Moderate
CVE-2026-55548 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
lucquach Credited to lucquach
Netty: Security Control Bypass via CORS Short-Circuit Failure Moderate
CVE-2026-56746 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
violetagg Credited to violetagg
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations Moderate
CVE-2026-41837 was published for org.springframework.data:spring-data-rest-core (Maven) Jun 10, 2026
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL Moderate
CVE-2026-41847 was published for org.springframework:spring-webflux (Maven) Jun 9, 2026
Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass Moderate
CVE-2026-37979 was published for org.keycloak:keycloak-services (Maven) May 19, 2026
Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration Moderate
CVE-2026-40966 was published for org.springframework.ai:spring-ai-advisors-vector-store (Maven) Apr 28, 2026
Seol-JY Credited to Seol-JY
Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false Moderate
CVE-2026-4628 was published for org.keycloak:keycloak-services (Maven) Mar 23, 2026
dnegreira Credited to dnegreira
Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API Moderate
CVE-2026-3429 was published for org.keycloak:keycloak-services (Maven) Mar 11, 2026
Ankush-Pathak Credited to Ankush-Pathak
Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash Moderate
CVE-2026-2742 was published for com.vaadin:flow-server (Maven) Mar 10, 2026
Jenkins global-build-stats Plugin missing permission check can result in graph IDs being enumerated Moderate
CVE-2025-58459 was published for org.jenkins-ci.plugins:global-build-stats (Maven) Sep 3, 2025
Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims Moderate
CVE-2025-1391 was published for org.keycloak:keycloak-services (Maven) Mar 10, 2025
Duplicate Advisory: Keycloak allows Incorrect Assignment of an Organization to a User Moderate
GHSA-rq4w-cjrr-h8w8 was published for org.keycloak:keycloak-services (Maven) Feb 17, 2025 withdrawn
WildFly improper RBAC permission Moderate
CVE-2025-23367 was published for org.wildfly.core:wildfly-server (Maven) Jan 31, 2025
Duplicate Advisory: Wildfly Server Role Based Access Control (RBAC) provider has Improper Access Control Moderate
GHSA-fcrw-mphx-7cxf was published for org.wildfly:wildfly-server (Maven) Jan 30, 2025 withdrawn
apollo-portal has potential unauthorized access issue Moderate
CVE-2024-43397 was published for com.ctrip.framework.apollo:apollo (Maven) Aug 20, 2024
Bonitasoft Runtime Community edition's contains an insecure direct object references vulnerability Moderate
CVE-2024-28087 was published for org.bonitasoft.engine:bonita-server (Maven) May 15, 2024
Privilege escalation in Liferay Portal Moderate
CVE-2022-45320 was published for com.liferay.portal:release.portal.bom (Maven) Feb 20, 2024
Broken access control in Silverpeas Moderate
CVE-2023-47321 was published for org.silverpeas.core:silverpeas-core-web (Maven) Dec 13, 2023
Broken access control in Silverpeas Moderate
CVE-2023-47325 was published for org.silverpeas.core:silverpeas-core-web (Maven) Dec 13, 2023
Broken access control in Silverpeas Moderate
CVE-2023-47327 was published for org.silverpeas.core:silverpeas-core-web (Maven) Dec 13, 2023
io.micronaut.security:micronaut-security-oauth2 has invalid IdTokenClaimsValidator logic on aud Moderate
CVE-2023-36820 was published for io.micronaut.security:micronaut-security-oauth2 (Maven) Oct 5, 2023
tommyli Credited to tommyli
PlantUML Improper Access Control vulnerability Moderate
CVE-2023-3431 was published for net.sourceforge.plantuml:plantuml-mit (Maven) Jun 27, 2023
Liferay portal unauthorized access to objects via OAuth 2 scope Moderate
CVE-2023-33946 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
Liferay portal has unauthorized access to object definition via search Moderate
CVE-2023-33947 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
ProTip! Advisories are also available from the GraphQL API