Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
582520
AlmaLinux
4473
Alpaquita
8418
Alpine
3981
Android
2912
BellSoft Hardened Containers
368
Bitnami
6590
Chainguard
5017
CleanStart
415
CRAN
13
crates.io
2051
Debian
44231
Echo
3007
GHC
3
GIT
82045
GitHub Actions
41
Go
5801
Hackage
27
Hex
47
Julia
332
Linux
16845
Mageia
5823
Maven
6187
MinimOS
14612
npm
215425
NuGet
1563
opam
11
openEuler
6007
openSUSE
10807
OSS-Fuzz
3784
Packagist
5765
Pub
10
PyPI
18019
Red Hat
18734
Rocky Linux
2764
Root
10822
RubyGems
1863
SUSE
19646
SwiftURL
47
Ubuntu
50890
VSCode
15
Wolfi
3109
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-6w48-2g9j-v9q5
Maven/org.apache.iotdb:iotdb-core
Apache IoTDB has an Improper Input Validation vulnerability
2 days ago
Fix available
Severity - 9.8 (Critical)
GHSA-74cf-pgh9-m5q2
Maven/org.apache.iotdb:iotdb-core
Apache IoTDB has an Insecure Default Configuration Vulnerability
2 days ago
Fix available
Severity - 9.8 (Critical)
GHSA-7xrh-hqfc-g7qr
Maven/org.apache.zookeeper:zookeeper
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
4 days ago
Fix available
Severity - 7.4 (High)
GHSA-crhr-qqj8-rpxc
Maven/org.apache.zookeeper:zookeeper
Apache ZooKeeper has improper handling of configuration values
4 days ago
Fix available
Severity - 8.7 (High)
GHSA-wjpw-4j6x-6rwh
Maven/org.eclipse.jetty:jetty-http
org.eclipse.jetty:jetty-http has different parsing of invalid URIs
5 days ago
Fix available
Severity - 3.7 (Low)
GHSA-6wcw-r64p-qrrw
Maven/org.cloudfoundry.identity:cloudfoundry-identity-server
Cloudfoundry UAA has logic error in the token revocation endpoint implementation
5 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-8cr3-vpxx-92cx
Maven/org.keycloak:keycloak-broker-saml
Keycloak SAML Broken has Authentication Bypass by Primary Weakness
5 days ago
No fix available
Severity - 8.8 (High)
GHSA-m297-3jv9-m927
Maven/org.keycloak:keycloak-services
Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
5 days ago
Fix available
Severity - 8.1 (High)
GHSA-xxh7-fcf3-rj7f
Maven/org.eclipse.jetty:jetty-server
The Eclipse Jetty Server Artifact has a Gzip request memory leak
5 days ago
Fix available
Severity - 7.5 (High)
GHSA-pm7g-w2cf-q238
Maven/org.pac4j:pac4j-jwt
pac4j-jwt: JwtAuthenticator Authentication Bypass via JWE-Wrapped PlainJWT
6 days ago
Fix available
Severity - 10.0 (Critical)
GHSA-6v53-7c9g-w56r
Maven/tools.jackson.core:jackson-core
jackson-core has Nesting Depth Constraint Bypass in
`
UTF8DataInputJsonParser
`
potentially allowing Resource Exhaustion
6 days ago
Fix available
Severity - 8.7 (High)
GHSA-h2xq-h7f9-vh6c
Maven/org.xwiki.contrib.blog:application-blog-ui
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
6 days ago
Fix available
Severity - 8.6 (High)
GHSA-c825-6ph3-4h84
Maven/org.apache.activemq:activemq-all
Maven/org.apache.activemq:activemq-mqtt
Maven/org.apache.activemq:apache-activemq
Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound
04 Mar
Fix available
Severity - 5.4 (Medium)
GHSA-fw88-pf9m-p947
Maven/org.apache.activemq:artemis-server
Maven/org.apache.artemis:artemis-server
Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions
04 Mar
Fix available
Severity - 9.3 (Critical)
GHSA-5fvg-qwcp-r325
Maven/org.apache.ranger:ranger-nifi-registry-plugin
Apache Ranger Vulnerable to Improper Validation of Certificate with Host Mismatch
03 Mar
Fix available
Severity - 5.3 (Medium)
GHSA-c87w-642h-m97h
Maven/org.apache.ranger:ranger-plugins-common
Apache Ranger has a Code Injection vulnerability
03 Mar
Fix available
Severity - 9.8 (Critical)
Load more...
Maven - OSV