An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

High
18 days ago

Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection GSA_kwCzR0hTQS1md3h4LXd2NDQtN3FmZ84ABNfS

maven org.springframework.cloud:spring-cloud-gateway-server-webflux
Low
18 days ago

Mattermost has an Observable Timing Discrepancy vulnerability GSA_kwCzR0hTQS14cjN3LXJtdmotZjZtN84ABNeq

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
18 days ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS02cTdtLXA4Y2MtOTk4cs4ABNe_

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Low
18 days ago

Mattermost has an Incorrect Authorization vulnerability GSA_kwCzR0hTQS00MjRoLXhqODctbTkzN84ABNe8

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
High
18 days ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS1yNnFqLTg5NGYtNWhyMs4ABNe1

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
18 days ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS03Y3IzLTM4am0tNnA0Nc4ABNex

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
18 days ago

Mattermost has a Missing Authorization vulnerability GSA_kwCzR0hTQS0zcTRxLXdxbTYtaHZmM84ABNe5

go github.com/mattermost/mattermost-server, github.com/mattermost/mattermost/server/v8
Moderate
19 days ago

OpenSearch Data Prepper uses deprecated SSL protocol identifier GSA_kwCzR0hTQS0yOGdnLThxcWotZmhoNc4ABNeM

maven org.opensearch.dataprepper.plugins:geoip-processor
Moderate
19 days ago

Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability GSA_kwCzR0hTQS1nd3E2LWZtdnAtcXA2OM4ABNdz

nuget Microsoft.NetCore.App.Runtime.win-x86, Microsoft.NetCore.App.Runtime.win-x64, Microsoft.NetCore.App.Runtime.win-arm64, Microsoft.NetCore.App.Runtime.win-arm, Microsoft.NetCore.App.Runtime.osx-x64, Microsoft.NetCore.App.Runtime.osx-arm64, Microsoft.NetCore.App.Runtime.linux-x64, Microsoft.NetCore.App.Runtime.linux-musl-x64, Microsoft.NetCore.App.Runtime.linux-musl-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-arm
High
19 days ago

Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability GSA_kwCzR0hTQS13M3E5LWZ4bTctajhmcc4ABNdy

nuget Microsoft.Build.Utilities.Core, Microsoft.Build, Microsoft.Build.Tasks.Core
Moderate
19 days ago

Apache Spark has Inadequate Encryption Strength GSA_kwCzR0hTQS02cDZ2LW02NHYtang4cc4ABNcA

maven org.apache.spark:spark-network-common_2.12, org.apache.spark:spark-network-common_2.13
Moderate
20 days ago

Magento allows incorrect authorization GSA_kwCzR0hTQS1yMzU1LTc1aHctcjhqZs4ABNa3

packagist magento/project-community-edition, magento/community-edition
Moderate
20 days ago

Magento vulnerable to privilege escalation due to incorrect authorization GSA_kwCzR0hTQS1xdndyLXAzaGotajZqZs4ABNa1

packagist magento/community-edition, magento/project-community-edition
Moderate
20 days ago

Magento vulnerable to stored Cross-Site Scripting (XSS) GSA_kwCzR0hTQS1wY3J4LXI0OWgteDJ3Nc4ABNay

packagist magento/community-edition, magento/project-community-edition
High
20 days ago

Magento vulnerable to stored Cross-Site Scripting (XSS) GSA_kwCzR0hTQS0yNzY4LTV3bXYtY2ZmZs4ABNav

packagist magento/community-edition, magento/project-community-edition
High
20 days ago

Magento provides incorrect authorization through a security feature bypass GSA_kwCzR0hTQS02OXg5LXhwMmotdzhnOM4ABNa2

packagist magento/project-community-edition, magento/community-edition
Critical
20 days ago

Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability GSA_kwCzR0hTQS01cnJ4LWpqanEtcTJyNc4ABNaI

nuget Microsoft.AspNetCore.App.Runtime.linux-musl-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.win-x86, Microsoft.AspNetCore.App.Runtime.win-x64, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.osx-x64, Microsoft.AspNetCore.App.Runtime.osx-arm64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.linux-musl-x64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
High
20 days ago

Argo Workflow has a Zipslip Vulnerability GSA_kwCzR0hTQS1wODR2LWd4dnctNzNwZs4ABNWi

go github.com/argoproj/argo-workflows/v3
Moderate
21 days ago

Liferay has Incorrect Permission Assignment for Critical Resource GSA_kwCzR0hTQS1qNGY3LWdqN3EteGc5bc4ABNUt

maven com.liferay:com.liferay.site.navigation.menu.item.asset.vocabulary
Moderate
21 days ago

Liferay Publications is vulnerable to Incorrect Authorization GSA_kwCzR0hTQS04OTR3LXc2NDMtcXZ4ds4ABNUT

maven com.liferay:com.liferay.change.tracking.web
Moderate
24 days ago

PowerJob OpenAPIController is missing authorization GSA_kwCzR0hTQS05d3E2LTg3aHctNm1oY84ABNQ1

maven tech.powerjob:powerjob-server-starter
Moderate
24 days ago

Liferay Portal Commerce is vulnerable to XSS through account "name" field GSA_kwCzR0hTQS1tNGc5LTVtZzYtZ2ZyM84ABNQR

maven com.liferay.commerce:com.liferay.commerce.order.web
Moderate
24 days ago

Liferay Portal is vulnerable to XSS through its workflow process builder GSA_kwCzR0hTQS14Y3Z3LWhoOTktcW03M84ABNQN

maven com.liferay:com.liferay.portal.workflow.kaleo.designer.web
Moderate
25 days ago

Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiers GSA_kwCzR0hTQS13cW0zLXczcDYteGpnbc4ABNKN

maven org.apache.flink:flink-connector-mysql-cdc, org.apache.flink:flink-connector-sqlserver-cdc, org.apache.flink:flink-connector-db2-cdc, org.apache.flink:flink-connector-oracle-cdc, org.apache.flink:flink-cdc-pipeline-connectors
Moderate
26 days ago

Keycloak Potential Variable Reference in Model Storage Services GSA_kwCzR0hTQS04aHhwLXFtcGgtdzVncc4ABNI4

maven org.keycloak:keycloak-model-storage-services

Filter by Severity

Filter by Ecosystem

Filter by Package

tensorflow 433 moodle/moodle 425 tensorflow-cpu 409 tensorflow-gpu 397 magento/community-edition 323 Microsoft.ChakraCore 247 org.jenkins-ci.main:jenkins-core 242 typo3/cms 179 com.liferay.portal:release.portal.bom 151 org.apache.tomcat:tomcat 140 github.com/mattermost/mattermost/server/v8 135 com.liferay.portal:release.dxp.bom 123 pimcore/pimcore 120 dolibarr/dolibarr 117 phpmyadmin/phpmyadmin 107 microweber/microweber 103 typo3/cms-core 101 drupal/core 99 apache-airflow 89 silverstripe/framework 89 Django 89 librenms/librenms 86 magento/project-community-edition 84 thorsten/phpmyfaq 74 drupal/drupal 73 github.com/mattermost/mattermost-server 69 com.fasterxml.jackson.core:jackson-databind 69 github.com/usememos/memos 68 concrete5/concrete5 67 salt 65 ansible 64 shopware/platform 63 actionpack 61 symfony/symfony 61 apache-superset 61 github.com/grafana/grafana 56 org.apache.struts:struts2-core 56 Plone 55 craftcms/cms 53 mlflow 53 shopware/core 51 github.com/hashicorp/vault 51 github.com/rancher/rancher 50 org.keycloak:keycloak-core 50 mautic/core 48 nova 48 baserproject/basercms 47 django 46 nokogiri 46 org.keycloak:keycloak-services 45 vyper 44 gradio 44 org.xwiki.platform:xwiki-platform-oldcore 43 org.elasticsearch:elasticsearch 43 matrix-synapse 43 rdiffweb 42 nilsteampassnet/teampass 42 plone 41 k8s.io/kubernetes 41 showdoc/showdoc 41 mantisbt/mantisbt 41 intelliants/subrion 40 org.apache.tomcat.embed:tomcat-embed-core 40 froxlor/froxlor 40 directus 39 picklescan 39 net.mingsoft:ms-mcms 38 snipe/snipe-it 38 com.thoughtworks.xstream:xstream 37 github.com/mattermost/mattermost-server/v6 37 github.com/argoproj/argo-cd/v2 36 com.jfinal:jfinal 36 moin 35 io.undertow:undertow-core 35 rack 35 github.com/answerdev/answer 34 org.jenkins-ci.plugins:script-security 33 parse-server 33 gogs.io/gogs 32 zendframework/zendframework1 32 github.com/hashicorp/nomad 31 keystone 31 github.com/hashicorp/consul 31 shopware/shopware 31 flowise 31 github.com/cilium/cilium 31 opencv-contrib-python 30 getgrav/grav 30 github.com/argoproj/argo-cd 30 opencv-python 30 electron 29 next 29 contao/core-bundle 29 github.com/docker/docker 29 vllm 28 pillow 28 mediawiki/core 28 Pillow 28 DotNetNuke.Core 28 org.opencms:opencms-core 27 centreon/centreon 27 org.apache.solr:solr-core 27 prestashop/prestashop 27 org.springframework.security:spring-security-core 26 github.com/traefik/traefik/v2 25 org.apache.tomcat:tomcat-catalina 25 org.eclipse.jetty:jetty-server 25 rubygems-update 25 pocketmine/pocketmine-mp 25 openssl-src 25 open-webui 25 magento/core 24 pyload-ng 24 surrealdb 24 org.keycloak:keycloak-parent 24 getkirby/cms 24 simplesamlphp/simplesamlphp 23 remdex/livehelperchat 23 grumpydictator/firefly-iii 23 puppet 23 ckb 22 zendframework/zendframework 22 activerecord 22 deno 22 phpoffice/phpspreadsheet 22 tribalsystems/zenario 22 org.apache.openmeetings:openmeetings-parent 22 laravel/framework 22 @openzeppelin/contracts-upgradeable 21 wasmtime 21 org.apache.nifi:nifi 21 glance 21 github.com/goharbor/harbor 21 @openzeppelin/contracts 21 org.xwiki.platform:xwiki-platform-web-templates 20 typo3/cms-backend 20 ethyca-fides 20 org.cloudfoundry.identity:cloudfoundry-identity-server 20 github.com/ethereum/go-ethereum 20 aim 20 Microsoft.AspNetCore.App.Runtime.win-x64 20 funadmin/funadmin 20 org.bouncycastle:bcprov-jdk15on 20 Microsoft.AspNetCore.App.Runtime.win-x86 20 cockpit-hq/cockpit 20 code.gitea.io/gitea 20 helm.sh/helm/v3 20 neutron 19 contao/contao 19 github.com/zitadel/zitadel 19 langchain 19 transformers 19 topthink/framework 19 com.vaadin:vaadin-bom 18 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 18 org.apache.jspwiki:jspwiki-main 18 Microsoft.AspNetCore.App.Runtime.win-arm 18 org.springframework:spring-core 18 golang.org/x/net 18 cobbler 18 mindsdb 18 forkcms/forkcms 18 genix/cms 18 openmage/magento-lts 17 org.apache.geode:geode-core 17 calibreweb 17 yetiforce/yetiforce-crm 17 Microsoft.AspNetCore.App.Runtime.linux-arm 17 Microsoft.AspNetCore.App.Runtime.win-arm64 17 opencart/opencart 17 mercurial 17 Microsoft.AspNetCore.App.Runtime.linux-arm64 17 Microsoft.NetCore.App.Runtime.win-arm64 17 github.com/openfga/openfga 17 Microsoft.AspNetCore.App.Runtime.linux-x64 17 Microsoft.NetCore.App.Runtime.win-arm 17 Microsoft.NetCore.App.Runtime.win-x64 17 cakephp/cakephp 17 Microsoft.NetCore.App.Runtime.win-x86 17 ezsystems/ezpublish-kernel 17 Microsoft.AspNetCore.App.Runtime.osx-x64 17 cryptography 17 OctoPrint 17 francoisjacquet/rosariosis 17 github.com/traefik/traefik/v3 17 org.apache.inlong:manager-pojo 17 notebook 17 sequelize 16 org.apache.ranger:ranger 16 vite 16 org.apache.dubbo:dubbo 16 paddlepaddle 16 ghost 16 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 16 phpbb/phpbb 16 org.apache.activemq:activemq-client 16 rusqlite 16 com.liferay.portal:com.liferay.portal.impl 16 PaddlePaddle 16 lollms 16

Filter by Repository

https://github.com/tensorflow/tensorflow 433 https://github.com/moodle/moodle 250 https://github.com/xwiki/xwiki-platform 222 https://github.com/chakra-core/ChakraCore 214 https://github.com/jenkinsci/jenkins 178 https://github.com/liferay/liferay-portal 167 https://github.com/django/django 119 https://github.com/apache/tomcat 118 https://github.com/pimcore/pimcore 116 https://github.com/apache/airflow 105 https://github.com/TYPO3/typo3 94 https://github.com/microweber/microweber 90 https://github.com/keycloak/keycloak 90 https://github.com/librenms/librenms 77 https://github.com/FasterXML/jackson-databind 70 https://github.com/rails/rails 70 https://github.com/thorsten/phpmyfaq 69 https://github.com/silverstripe/silverstripe-framework 68 https://github.com/usememos/memos 68 https://github.com/kubernetes/kubernetes 66 https://github.com/symfony/symfony 64 https://github.com/Dolibarr/dolibarr 60 https://github.com/mattermost/mattermost 59 https://github.com/ansible/ansible 59 https://github.com/python-pillow/Pillow 52 https://github.com/spring-projects/spring-framework 51 https://github.com/argoproj/argo-cd 50 https://github.com/grafana/grafana 47 https://github.com/apache/struts 47 https://github.com/mautic/mautic 46 https://github.com/rancher/rancher 46 https://github.com/phpmyadmin/phpmyadmin 45 https://github.com/concretecms/concretecms 44 https://github.com/vyperlang/vyper 44 https://github.com/shopware/platform 43 https://github.com/saltstack/salt 42 https://github.com/ikus060/rdiffweb 42 https://github.com/craftcms/cms 41 https://github.com/directus/directus 41 https://github.com/shopware/shopware 40 https://github.com/star7th/showdoc 39 https://github.com/gradio-app/gradio 39 https://github.com/mmaitre314/picklescan 39 https://github.com/openstack/nova 38 https://github.com/dotnet/runtime 38 https://github.com/magento/magento2 38 https://github.com/mantisbt/mantisbt 38 https://github.com/plone/Products.CMFPlone 37 https://github.com/x-stream/xstream 37 https://github.com/octobercms/october 36 https://github.com/umbraco/Umbraco-CMS 35 https://github.com/mlflow/mlflow 35 https://github.com/sparklemotion/nokogiri 35 https://github.com/answerdev/answer 34 https://github.com/apache/activemq 34 https://github.com/parse-community/parse-server 33 https://github.com/opencv/opencv 32 https://github.com/go-gitea/gitea 32 https://github.com/matrix-org/synapse 32 https://github.com/apache/inlong 31 https://github.com/PaddlePaddle/Paddle 31 https://github.com/cilium/cilium 31 https://github.com/snipe/snipe-it 30 https://github.com/contao/contao 30 https://github.com/strapi/strapi 29 https://github.com/rack/rack 29 https://github.com/openstack/keystone 28 https://github.com/electron/electron 28 https://github.com/CVEProject/cvelist 28 https://github.com/FlowiseAI/Flowise 28 https://github.com/gogs/gogs 28 https://github.com/netty/netty 27 https://github.com/froxlor/froxlor 26 https://github.com/baserproject/basercms 26 https://github.com/github/advisory-database 26 https://github.com/geoserver/geoserver 26 https://github.com/apache/nifi 26 https://github.com/vercel/next.js 25 https://github.com/pmmp/PocketMine-MP 25 https://github.com/vllm-project/vllm 25 https://github.com/bcgit/bc-java 25 https://github.com/traefik/traefik 25 https://github.com/denoland/deno 25 https://github.com/surrealdb/surrealdb 25 https://github.com/zitadel/zitadel 25 https://github.com/langchain-ai/langchain 25 https://github.com/apache/cxf 24 https://github.com/hashicorp/consul 24 https://github.com/getgrav/grav 24 https://github.com/run-llama/llama_index 24 https://github.com/pyload/pyload 24 https://github.com/firefly-iii/firefly-iii 23 https://github.com/bytecodealliance/wasmtime 23 https://github.com/TYPO3/TYPO3.CMS 23 https://github.com/dnnsoftware/Dnn.Platform 23 https://github.com/nilsteampassnet/TeamPass 23 https://github.com/livehelperchat/livehelperchat 23 https://github.com/eclipse/jetty.project 23 https://github.com/PrestaShop/PrestaShop 23 https://github.com/moby/moby 23 https://github.com/PHPOffice/PhpSpreadsheet 22 https://github.com/nervosnetwork/ckb 22 https://github.com/jenkinsci/script-security-plugin 22 https://github.com/helm/helm 22 https://github.com/getkirby/kirby 22 https://github.com/laravel/framework 21 https://github.com/undertow-io/undertow 21 https://github.com/hashicorp/vault 21 https://github.com/OpenZeppelin/openzeppelin-contracts 21 https://github.com/goharbor/harbor 21 https://github.com/opencast/opencast 20 https://github.com/jeecgboot/jeecg-boot 20 https://github.com/OpenNMS/opennms 20 https://github.com/simplesamlphp/simplesamlphp 20 https://github.com/funadmin/funadmin 20 https://github.com/ethyca/fides 20 https://github.com/TYPO3-CMS/core 19 https://github.com/cloudfoundry/uaa 19 https://github.com/backstage/backstage 19 https://github.com/huggingface/transformers 19 https://github.com/alkacon/opencms-core 19 https://github.com/intelliants/subrion 19 https://github.com/nilsteampassnet/teampass 19 https://github.com/apache/camel 18 https://github.com/vaadin/platform 18 https://github.com/rubygems/rubygems 18 https://github.com/liufee/cms 17 https://github.com/mindsdb/mindsdb 17 https://github.com/containerd/containerd 17 https://github.com/apache/kylin 17 https://github.com/ethereum/go-ethereum 17 https://github.com/vantage6/vantage6 17 https://github.com/OpenMage/magento-lts 17 https://github.com/openfga/openfga 17 https://github.com/etcd-io/etcd 16 https://github.com/yetiforcecompany/yetiforcecrm 16 https://github.com/vitejs/vite 16 https://github.com/forkcms/forkcms 16 https://github.com/dotnet/aspnetcore 16 https://github.com/rusqlite/rusqlite 16 https://github.com/quarkusio/quarkus 16 https://github.com/hashicorp/nomad 16 https://github.com/pyca/cryptography 16 https://github.com/tinymce/tinymce 16 https://github.com/sequelize/sequelize 16 https://github.com/decidim/decidim 15 https://github.com/aio-libs/aiohttp 15 https://github.com/centreon/centreon 15 https://github.com/OPCFoundation/UA-.NETStandard 15 https://github.com/containers/podman 15 https://github.com/dompdf/dompdf 15 https://github.com/puppetlabs/puppet 15 https://github.com/drupal/core 15 https://github.com/MobSF/Mobile-Security-Framework-MobSF 15 https://github.com/spring-projects/spring-security 15 https://github.com/PHPMailer/PHPMailer 15 https://github.com/thorsten/phpMyFAQ 15 https://github.com/zendframework/zendframework 15 https://github.com/cobbler/cobbler 15 https://github.com/xuxueli/xxl-job 15 https://github.com/ckeditor/ckeditor4 15 https://github.com/nodejs/undici 15 https://github.com/pgadmin-org/pgadmin4 14 https://github.com/ImageMagick/ImageMagick 14 https://github.com/golang/go 14 https://github.com/twisted/twisted 14 https://github.com/rails/rails-html-sanitizer 14 https://github.com/TryGhost/Ghost 14 https://github.com/pimcore/admin-ui-classic-bundle 14 https://github.com/dpgaspar/Flask-AppBuilder 14 https://github.com/publify/publify 14 https://github.com/apache/superset 14 https://github.com/janeczku/calibre-web 14 https://github.com/Graylog2/graylog2-server 14 https://github.com/cosmos/cosmos-sdk 14 https://github.com/cockpit-hq/cockpit 14 https://github.com/apache/zeppelin 14 https://github.com/urllib3/urllib3 14 https://github.com/ming-soft/MCMS 14 https://github.com/openbao/openbao 13 https://github.com/h2oai/h2o-3 13 https://github.com/modoboa/modoboa 13 https://github.com/1Panel-dev/1Panel 13 https://github.com/OpenRefine/OpenRefine 13 https://github.com/opencontainers/runc 13 https://github.com/apache/dolphinscheduler 13 https://github.com/dromara/hutool 13 https://github.com/zenml-io/zenml 13 https://github.com/laurent22/joplin 13 https://github.com/swagger-api/swagger-ui 13 https://github.com/OctoPrint/OctoPrint 12 https://sourceforge.net/projects/phpmyadmin.sourceforge.net 12 https://github.com/smarty-php/smarty 12 https://github.com/nautobot/nautobot 12 https://github.com/n8n-io/n8n 12 https://github.com/DSpace/DSpace 12 https://github.com/patriksimek/vm2 12 https://github.com/modxcms/revolution 12 https://github.com/getsentry/sentry 12