Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
1932362
AlmaLinux
5498
Alpaquita
12401
Alpine
4355
Android
2912
Azure Linux
12016
BellSoft Hardened Containers
612
Bitnami
8541
Chainguard
851240
CleanStart
1988
CRAN
14
crates.io
2603
Debian
61938
Docker Hardened Images
1
Echo
4306
GHC
3
GIT
95684
GitHub Actions
54
Go
8523
Hackage
32
Hex
219
Julia
1548
Linux
26003
Mageia
6096
Maven
6783
MinimOS
103609
npm
225743
NuGet
1818
opam
24
openEuler
7498
openSUSE
13830
OSS-Fuzz
3983
Packagist
6774
Pub
11
PyPI
24265
Red Hat
21891
Rocky Linux
3842
Root
18789
RubyGems
4583
SUSE
22121
SwiftURL
58
TuxCare
8256
Ubuntu
59211
VSCode
20
Wolfi
292666
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-p9jm-q85p-7mcp
Maven/io.netty:netty-codec-redis
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
yesterday
Fix available
Severity - 6.5 (Medium)
GHSA-pmhh-3w7g-xqp8
Maven/org.jsoup:jsoup
jsoup: Cleaner may expose markup with custom raw-text elements
2 days ago
Fix available
Severity - 4.7 (Medium)
GHSA-pjp7-q6wp-97qx
Maven/org.geonetwork-opensource:geonetwork
core-geonetwork has an Open Redirect Bypass
31 Jul
Fix available
Severity - 4.8 (Medium)
GHSA-93wv-jw9v-4972
Maven/io.netty:netty-codec-http2
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
31 Jul
Fix available
Severity - 7.5 (High)
GHSA-88fw-v6x4-3f58
Maven/org.springframework.data:spring-data-commons
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
31 Jul
Fix available
Severity - 7.5 (High)
GHSA-fq3f-m5qm-99f5
Maven/io.opentelemetry.javaagent:opentelemetry-javaagent
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
29 Jul
Fix available
Severity - 5.3 (Medium)
GHSA-7c26-995w-6f47
Maven/org.verapdf:parser
veraPDF Parser DoS via PostScript Type 1 Font Programs
29 Jul
Fix available
Severity - 6.9 (Medium)
GHSA-cg9x-g3gm-h5h6
Maven/org.verapdf:validation-model
Maven/org.verapdf:validation-model-jakarta
veraPDF-validatio: Use of Default
`
DocumentBuilderFactory
`
leads to XXE When Processing Untrusted PDFs
29 Jul
Fix available
Severity - 6.5 (Medium)
GHSA-3jh7-wm29-q568
Maven/org.verapdf:validation-model
Maven/org.verapdf:validation-model-jakarta
veraPDF Validation XXE via Rich Text
29 Jul
Fix available
Severity - 8.7 (High)
GHSA-36mm-w85j-3q2j
Maven/org.verapdf:validation-model
Maven/org.verapdf:validation-model-jakarta
veraPDF Validation XXE via XFA
29 Jul
Fix available
Severity - 8.7 (High)
GHSA-85rg-p3fr-xc2f
Maven/com.quietterminal:qti-neon
PyPI/qti-neon
npm/qti-neon
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
28 Jul
No fix available
Severity - 8.6 (High)
GHSA-4r9r-4425-74p7
Maven/com.cedarpolicy:cedar-java
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
28 Jul
Fix available
Severity - 8.8 (High)
GHSA-28f5-38xr-jh2w
Maven/io.appium:java-client
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
28 Jul
Fix available
Severity - 8.2 (High)
GHSA-4j38-rw27-97gx
Maven/org.xwiki.contrib:discussions-server
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
27 Jul
Fix available
Severity - 6.5 (Medium)
GHSA-fp43-vj7g-pg92
Maven/org.omnifaces:omnifaces
OmniFaces: Forged combined-resource IDs and related output/push boundaries
24 Jul
Fix available
Severity - 7.5 (High)
GHSA-7ppr-r889-mcf2
Maven/org.http4s:http4s-blaze-server_2.12
Maven/org.http4s:http4s-blaze-server_2.13
Maven/org.http4s:http4s-blaze-server_3
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
24 Jul
Fix available
Severity - 7.5 (High)
Load more...
Maven - OSV