GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,274
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,419
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
335 advisories
Filter by severity
Missing permission check in Jenkins ThreadFix Plugin
Moderate
CVE-2022-34210
was published
for
org.jenkins-ci.plugins:threadfix
(Maven)
Jun 24, 2022
Cross-Site Request Forgery in Jenkins vRealize Orchestrator Plugin
Moderate
CVE-2022-34211
was published
for
org.jenkins-ci.plugins:vmware-vrealize-orchestrator
(Maven)
Jun 24, 2022
Improper authorization in Jenkins Embeddable Build Status Plugin bypasses ViewStatus permission requirement
Moderate
CVE-2022-34180
was published
for
org.jenkins-ci.plugins:embeddable-build-status
(Maven)
Jun 24, 2022
Missing permission check in Jenkins Convertigo Mobile Platform Plugin
Moderate
CVE-2022-34201
was published
for
com.convertigo.jenkins.plugins:convertigo-mobile-platform
(Maven)
Jun 24, 2022
Path Traversal vulnerability in Jenkins Embeddable Build Status Plugin
Moderate
CVE-2022-34179
was published
for
org.jenkins-ci.plugins:embeddable-build-status
(Maven)
Jun 24, 2022
Cross-Site Request Forgery in Jenkins Convertigo Mobile Platform Plugin
Moderate
CVE-2022-34200
was published
for
com.convertigo.jenkins.plugins:convertigo-mobile-platform
(Maven)
Jun 24, 2022
Cross-Site Request Forgery in Jenkins EasyQA Plugin
Moderate
CVE-2022-34203
was published
for
com.geteasyqa:easyqa
(Maven)
Jun 24, 2022
Plaintext Storage of a Password in Jenkins Convertigo Mobile Platform Plugin
Moderate
CVE-2022-34199
was published
for
com.convertigo.jenkins.plugins:convertigo-mobile-platform
(Maven)
Jun 24, 2022
Agent-to-controller security bypass in Jenkins xUnit Plugin
Moderate
CVE-2022-34181
was published
for
org.jenkins-ci.plugins:xunit
(Maven)
Jun 24, 2022
Observable timing discrepancy allows determining username validity in Jenkins
Moderate
CVE-2022-34174
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 24, 2022
Missing permission check in Jenkins XebiaLabs XL Deploy Plugin allows enumerating credentials IDs
Moderate
CVE-2021-21662
was published
for
com.xebialabs.deployit.ci:deployit-plugin
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Scriptler Plugin
Moderate
CVE-2021-21700
was published
for
org.jenkins-ci.plugins:scriptler
(Maven)
May 24, 2022
XXE vulnerability in Jenkins pom2config Plugin
Moderate
CVE-2021-43576
was published
for
org.jenkins-ci.plugins:pom2config
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Active Choices Plugin
Moderate
CVE-2021-21699
was published
for
org.biouno:uno-choice
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Performance Plugin
Moderate
CVE-2021-21701
was published
for
org.jenkins-ci.plugins:performance
(Maven)
May 24, 2022
Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files
Moderate
CVE-2021-21698
was published
for
org.jenkins-ci.plugins:subversion
(Maven)
May 24, 2022
Path traversal vulnerability on Windows in Jenkins
Moderate
CVE-2021-21683
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Improper handling of equivalent directory names on Windows in Jenkins
Moderate
CVE-2021-21682
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Git Plugin
Moderate
CVE-2021-21684
was published
for
org.jenkins-ci.plugins:git
(Maven)
May 24, 2022
Password stored in plain text by Jenkins Nomad Plugin
Moderate
CVE-2021-21681
was published
for
org.jenkins-ci.plugins:nomad
(Maven)
May 24, 2022
Missing permission check in Jenkins requests-plugin Plugin allows viewing pending requests
Moderate
CVE-2021-21674
was published
for
org.jenkins-ci.plugins:requests
(Maven)
May 24, 2022
Improper permission checks allow canceling queue items and aborting builds in Jenkins
Moderate
CVE-2021-21670
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
CSRF vulnerabilities in Jenkins requests-plugin Plugin
Moderate
CVE-2021-21675
was published
for
org.jenkins-ci.plugins:requests
(Maven)
May 24, 2022
Missing permission check in Jenkins requests-plugin Plugin allows sending emails
Moderate
CVE-2021-21676
was published
for
org.jenkins-ci.plugins:requests
(Maven)
May 24, 2022
Open redirect vulnerability in Jenkins CAS Plugin
Moderate
CVE-2021-21673
was published
for
org.jenkins-ci.plugins:cas-plugin
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API