GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
335 advisories
Filter by severity
Stored XSS vulnerability in Jenkins Active Choices Plugin
Moderate
CVE-2021-21616
was published
for
org.biouno:uno-choice
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Artifact Repository Parameter Plugin
Moderate
CVE-2021-21622
was published
for
io.jenkins.plugins:artifact-repository-parameter
(Maven)
May 24, 2022
XSS vulnerability in Jenkins Claim Plugin
Moderate
CVE-2021-21619
was published
for
org.jenkins-ci.plugins:claim
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Repository Connector Plugin
Moderate
CVE-2021-21618
was published
for
org.jenkins-ci.plugins:repository-connector
(Maven)
May 24, 2022
Time-of-check Time-of-use (TOCTOU) Race Condition in Jenkins
Moderate
CVE-2021-21615
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins on new item page
Moderate
CVE-2021-21611
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Credentials stored in plain text by Jenkins Bumblebee HP ALM Plugin
Moderate
CVE-2021-21614
was published
for
org.jenkins-ci.plugins:bumblebee
(Maven)
May 24, 2022
Excessive memory allocation in graph URLs leads to denial of service in Jenkins
Moderate
CVE-2021-21607
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
XSS vulnerability in Jenkins TICS Plugin
Moderate
CVE-2021-21613
was published
for
io.jenkins.plugins:tics
(Maven)
May 24, 2022
Reflected XSS vulnerability in Jenkins markup formatter preview
Moderate
CVE-2021-21610
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Credentials stored in plain text by Jenkins TraceTronic ECU-TEST Plugin
Moderate
CVE-2021-21612
was published
for
de.tracetronic.jenkins.plugins:ecutest
(Maven)
May 24, 2022
Missing permission check for paths with specific prefix in Jenkins
Moderate
CVE-2021-21609
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins button labels
Moderate
CVE-2021-21608
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
XSS vulnerability in Jenkins notification bar
Moderate
CVE-2021-21603
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Arbitrary file existence check in file fingerprints in Jenkins
Moderate
CVE-2021-21606
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Arbitrary file read vulnerability in workspace browsers in Jenkins
Moderate
CVE-2021-21602
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Missing permission checks in Jenkins Chaos Monkey Plugin
Moderate
CVE-2020-2323
was published
for
io.jenkins.plugins:chaos-monkey
(Maven)
May 24, 2022
Passwords stored in plain text by Mail Commander Plugin for Jenkins-ci Plugin
Moderate
CVE-2020-2318
was published
for
org.jenkins-ci.plugins:mailcommander
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins FindBugs Plugin
Moderate
CVE-2020-2317
was published
for
org.jvnet.hudson.plugins:findbugs
(Maven)
May 24, 2022
Missing permission checks in Jenkins Ansible Plugin allow enumerating credentials IDs
Moderate
CVE-2020-2310
was published
for
org.jenkins-ci.plugins:ansible
(Maven)
May 24, 2022
Missing permission check in Jenkins AWS Global Configuration Plugin allows replacing plugin configuration
Moderate
CVE-2020-2311
was published
for
io.jenkins.plugins:aws-global-configuration
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Visualworks Store Plugin
Moderate
CVE-2020-2315
was published
for
org.jenkins-ci.plugins:visualworks-store
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Static Analysis Utilities Plugin
Moderate
CVE-2020-2316
was published
for
org.jvnet.hudson.plugins:analysis-core
(Maven)
May 24, 2022
Password written to the build log by Jenkins SQLPlus Script Runner Plugin
Moderate
CVE-2020-2312
was published
for
org.jenkins-ci.plugins:sqlplus-script-runner
(Maven)
May 24, 2022
Missing permission checks in Jenkins Azure Key Vault Plugin allow enumerating credentials IDs
Moderate
CVE-2020-2313
was published
for
org.jenkins-ci.plugins:azure-keyvault
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API