GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
335 advisories
Filter by severity
Improper credentials masking in Jenkins HashiCorp Vault Plugin
Moderate
CVE-2022-23109
was published
for
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
(Maven)
Jan 13, 2022
Stored XSS vulnerability in Jenkins Publish Over SSH Plugin
Moderate
CVE-2022-23110
was published
for
org.jenkins-ci.plugins:publish-over-ssh
(Maven)
Jan 13, 2022
CSRF vulnerability and missing permission checks in Jenkins Publish Over SSH Plugin
Moderate
CVE-2022-23111
was published
for
org.jenkins-ci.plugins:publish-over-ssh
(Maven)
Jan 13, 2022
Stored XSS vulnerability in Jenkins Git Plugin
Moderate
CVE-2021-21684
was published
for
org.jenkins-ci.plugins:git
(Maven)
May 24, 2022
Path traversal vulnerability in Jenkins Publish Over SSH Plugin
Moderate
CVE-2022-23113
was published
for
org.jenkins-ci.plugins:publish-over-ssh
(Maven)
Jan 13, 2022
CSRF vulnerability in Jenkins batch task Plugin
Moderate
CVE-2022-23115
was published
for
org.jenkins-ci.plugins:batch-task
(Maven)
Jan 13, 2022
Stored XSS vulnerability in Jenkins Scriptler Plugin
Moderate
CVE-2021-21667
was published
for
org.jenkins-ci.plugins:scriptler
(Maven)
Jan 6, 2022
Cross-site scripting in Jenkins Kiuwan Plugin
Moderate
CVE-2021-21666
was published
for
org.jenkins-ci.plugins:kiuwanJenkinsPlugin
(Maven)
Jun 16, 2021
Cross-Site Request Forgery in Jenkins Credentials Plugin
Moderate
CVE-2021-21648
was published
for
org.jenkins-ci.plugins:credentials
(Maven)
Jun 16, 2021
Missing Authorization in Jenkins P4 plugin
Moderate
CVE-2021-21654
was published
for
org.jenkins-ci.plugins:p4
(Maven)
Jun 16, 2021
Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps
Moderate
CVE-2020-2181
was published
for
org.jenkins-ci.plugins:credentials-binding
(Maven)
May 24, 2022
Missing permission checks in Jenkins Amazon EC2 Plugin
Moderate
CVE-2020-2091
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
Jenkins vulnerable to UDP amplification reflection attack
Moderate
CVE-2020-2100
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Jenkins Diagnostic page exposed session cookies
Moderate
CVE-2020-2103
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Memory usage graphs accessible to anyone with Overall/Read
Moderate
CVE-2020-2104
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
DoS vulnerability in bundled XStream library in Jenkins Core
Moderate
CVE-2022-0538
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Feb 10, 2022
Path traversal vulnerability on Windows in Jenkins
Moderate
CVE-2021-21683
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows enumerating credentials IDs
Moderate
CVE-2021-21662
was published
for
com.xebialabs.deployit.ci:deployit-plugin
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Active Choices Plugin
Moderate
CVE-2021-21616
was published
for
org.biouno:uno-choice
(Maven)
May 24, 2022
Lack of type validation in agent related REST API in Jenkins
Moderate
CVE-2021-21639
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
XSS vulnerability in Jenkins Markdown Formatter Plugin
Moderate
CVE-2021-21660
was published
for
io.jenkins.plugins:markdown-formatter
(Maven)
May 24, 2022
Improper permission checks in Jenkins Copy Artifact Plugin
Moderate
CVE-2020-2183
was published
for
org.jenkins-ci.plugins:copyartifact
(Maven)
May 24, 2022
Users with Overall/Read access could enumerate credentials IDs in Jenkins Fortify on Demand Plugin
Moderate
CVE-2020-2202
was published
for
org.jenkins-ci.plugins:fortify-on-demand-uploader
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Active Choices Plugin
Moderate
CVE-2020-2289
was published
for
org.biouno:uno-choice
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Active Choices Plugin
Moderate
CVE-2020-2290
was published
for
org.biouno:uno-choice
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API