GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            108 advisories
        Filter by severity
        
      
      
    
                    
                      Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
                    
                      
  High
                    
                
                      
                        CVE-2025-41253
                      
                      was published
                        for
                        
                          org.springframework.cloud:spring-cloud-gateway-server-webflux
                        
                        (Maven)
                      Oct 16, 2025 
                    
                  
                    
                      Hutool allows remote code execution (RCE) via the QLExpressEngine class
                    
                      
  High
                    
                
                      
                        CVE-2025-56769
                      
                      was published
                        for
                        
                          cn.hutool:hutool-extra
                        
                        (Maven)
                      Sep 26, 2025 
                    
                  
                    
                      An improper neutralization of inputs used in expression
language allows remote code execution...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-3322
                      
                      was published
                      Jun 6, 2025 
                    
                  
                    
                      IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 
12.0.0 through 12.0.4
is vulnerable to an...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-51466
                      
                      was published
                      Dec 20, 2024 
                    
                  
                    
                      QOS.CH logback-core Expression Language Injection vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-12798
                      
                      was published
                        for
                        
                          ch.qos.logback:logback-core
                        
                        (Maven)
                      Dec 19, 2024 
                    
                  
                    
                      A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-9672
                      
                      was published
                      Dec 10, 2024 
                    
                  
                    
                      A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-7552
                      
                      was published
                      Aug 6, 2024 
                    
                  
                    
                      Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-5828
                      
                      was published
                      Aug 6, 2024 
                    
                  
                    
                      Voltronic Power ViewPower Pro Expression Language Injection Remote Code Execution Vulnerability....
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-51593
                      
                      was published
                      May 3, 2024 
                    
                  
                    
                      Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-0715
                      
                      was published
                      Feb 20, 2024 
                    
                  
                    
                      Archive, check and export commands in Chef InSpec
prior to 4.56.58 and 5.22.29 allow local...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-42658
                      
                      was published
                      Oct 31, 2023 
                    
                  
                    
                      Expression Language Injection vulnerability in Hitachi Replication Manager on Windows, Linux,...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-4146
                      
                      was published
                      Jul 18, 2023 
                    
                  
                    
                      Apache Ambari Expression Language Injection vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2022-45855
                      
                      was published
                        for
                        
                          org.apache.ambari:ambari
                        
                        (Maven)
                      Jul 12, 2023 
                    
                  
                    
                      Apache Ambari Expression Language Injection vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2022-42009
                      
                      was published
                        for
                        
                          org.apache.ambari:ambari
                        
                        (Maven)
                      Jul 12, 2023 
                    
                  
                    
                      Apache Jena Expression Language Injection vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2023-32200
                      
                      was published
                        for
                        
                          org.apache.jena:jena
                        
                        (Maven)
                      Jul 12, 2023 
                    
                  
                    
                      Arbitrary javascript injection in Apache Jena
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-22665
                      
                      was published
                        for
                        
                          org.apache.jena:jena
                        
                        (Maven)
                      Apr 25, 2023 
                    
                  
                    
                      Spring Framework vulnerable to denial of service
                    
                      
  High
                    
                
                      
                        CVE-2023-20863
                      
                      was published
                        for
                        
                          org.springframework:spring-expression
                        
                        (Maven)
                      Apr 13, 2023 
                    
                  
                    
                      Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-27821
                      
                      was published
                      Mar 28, 2023 
                    
                  
                    
                      Spring Framework vulnerable to denial of service via specially crafted SpEL expression
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-20861
                      
                      was published
                        for
                        
                          org.springframework:spring-expression
                        
                        (Maven)
                      Mar 23, 2023 
                    
                  
                    
                      Liima before 1.17.28 allows server-side template injection.
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-26092
                      
                      was published
                      Feb 20, 2023 
                    
                  
                    
                      TYPO3 CMS vulnerable to Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-23504
                      
                      was published
                        for
                        
                          typo3/cms
                        
                        (Composer)
                      Dec 13, 2022 
                    
                  
                    
                      Nepxion Discovery vulnerable to SpEL Injection leading to Remote Code Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2022-23463
                      
                      was published
                        for
                        
                          com.nepxion:discovery
                        
                        (Maven)
                      Sep 25, 2022 
                    
                  
                    
                      A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 ...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-34466
                      
                      was published
                      Jul 13, 2022 
                    
                  
                    
                      SpEL Injection in Spring Data MongoDB
                    
                      
  Critical
                    
                
                      
                        CVE-2022-22980
                      
                      was published
                        for
                        
                          org.springframework.data:spring-data-mongodb
                        
                        (Maven)
                      Jun 24, 2022 
                    
                  
                    
                      In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-26134
                      
                      was published
                      Jun 4, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API