Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
1939333
AlmaLinux
5552
Alpaquita
12738
Alpine
4374
Android
2912
Azure Linux
12016
BellSoft Hardened Containers
616
Bitnami
8541
Chainguard
852567
CleanStart
1988
CRAN
14
crates.io
2630
Debian
62474
Docker Hardened Images
1
Echo
4347
GHC
3
GIT
96593
GitHub Actions
54
Go
8543
Hackage
32
Hex
223
Julia
1644
Linux
26309
Mageia
6101
Maven
6810
MinimOS
105278
npm
226011
NuGet
1830
opam
24
openEuler
7498
openSUSE
13877
OSS-Fuzz
3986
Packagist
6790
Pub
11
PyPI
24325
Red Hat
22016
Rocky Linux
3876
Root
18878
RubyGems
4583
SUSE
22229
SwiftURL
58
TuxCare
8405
Ubuntu
59642
VSCode
20
Wolfi
292914
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-p9jm-q85p-7mcp
Maven/io.netty:netty-codec-redis
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
5 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-pmhh-3w7g-xqp8
Maven/org.jsoup:jsoup
jsoup: Cleaner may expose markup with custom raw-text elements
6 days ago
Fix available
Severity - 4.7 (Medium)
GHSA-pjp7-q6wp-97qx
Maven/org.geonetwork-opensource:geonetwork
core-geonetwork has an Open Redirect Bypass
31 Jul
Fix available
Severity - 4.8 (Medium)
GHSA-93wv-jw9v-4972
Maven/io.netty:netty-codec-http2
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
31 Jul
Fix available
Severity - 7.5 (High)
GHSA-88fw-v6x4-3f58
Maven/org.springframework.data:spring-data-commons
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
31 Jul
Fix available
Severity - 7.5 (High)
GHSA-fq3f-m5qm-99f5
Maven/io.opentelemetry.javaagent:opentelemetry-javaagent
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
29 Jul
Fix available
Severity - 5.3 (Medium)
GHSA-7c26-995w-6f47
Maven/org.verapdf:parser
veraPDF Parser DoS via PostScript Type 1 Font Programs
29 Jul
Fix available
Severity - 6.9 (Medium)
GHSA-cg9x-g3gm-h5h6
Maven/org.verapdf:validation-model
Maven/org.verapdf:validation-model-jakarta
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
29 Jul
Fix available
Severity - 6.5 (Medium)
GHSA-3jh7-wm29-q568
Maven/org.verapdf:validation-model
Maven/org.verapdf:validation-model-jakarta
veraPDF Validation XXE via Rich Text
29 Jul
Fix available
Severity - 8.7 (High)
GHSA-36mm-w85j-3q2j
Maven/org.verapdf:validation-model
Maven/org.verapdf:validation-model-jakarta
veraPDF Validation XXE via XFA
29 Jul
Fix available
Severity - 8.7 (High)
GHSA-85rg-p3fr-xc2f
Maven/com.quietterminal:qti-neon
PyPI/qti-neon
npm/qti-neon
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
28 Jul
No fix available
Severity - 8.6 (High)
GHSA-4r9r-4425-74p7
Maven/com.cedarpolicy:cedar-java
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
28 Jul
Fix available
Severity - 8.8 (High)
GHSA-28f5-38xr-jh2w
Maven/io.appium:java-client
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
28 Jul
Fix available
Severity - 8.2 (High)
GHSA-4j38-rw27-97gx
Maven/org.xwiki.contrib:discussions-server
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
27 Jul
Fix available
Severity - 6.5 (Medium)
GHSA-fp43-vj7g-pg92
Maven/org.omnifaces:omnifaces
OmniFaces: Forged combined-resource IDs and related output/push boundaries
24 Jul
Fix available
Severity - 7.5 (High)
GHSA-7ppr-r889-mcf2
Maven/org.http4s:http4s-blaze-server_2.12
Maven/org.http4s:http4s-blaze-server_2.13
Maven/org.http4s:http4s-blaze-server_3
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
24 Jul
Fix available
Severity - 7.5 (High)
Load more...
Maven - OSV