GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
324 advisories
Filter by severity
Jenkins youtrack-plugin Plugin stored credentials in plain text
Low
CVE-2019-10287
was published
for
org.jenkins-ci.plugins:youtrack-plugin
(Maven)
May 13, 2022
Jenkins Minio Storage Plugin stores credentials in plain text
Low
CVE-2019-10285
was published
for
org.jenkins-ci.plugins:minio-storage
(Maven)
May 13, 2022
Jenkins Koji Plugin stores credentials in plain text
Low
CVE-2019-10298
was published
for
org.jenkins-ci.plugins:koji
(Maven)
May 13, 2022
Jenkins Netsparker Enterprise Scan Plugin stored credentials in plain text
Low
CVE-2019-10291
was published
for
org.jenkins-ci.plugins:netsparker-cloud-scan
(Maven)
May 13, 2022
Jenkins Sametime Plugin stores credentials in plain text
Low
CVE-2019-10297
was published
for
org.jenkins-ci.plugins:sametime
(Maven)
May 13, 2022
Jenkins CloudCoreo DeployTime Plugin stores credentials in plain text
Low
CVE-2019-10299
was published
for
com.cloudcoreo.plugins:cloudcoreo-deploytime
(Maven)
May 13, 2022
Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials in plain text
Low
CVE-2019-10281
was published
for
org.jenkins-ci.plugins:relution-publisher
(Maven)
May 13, 2022
Jenkins Serena SRA Deploy Plugin stores credentials in plain text
Low
CVE-2019-10296
was published
for
com.urbancode.ds.jenkins.plugins:sra-deploy
(Maven)
May 13, 2022
ActiveMQ's OpenWire protocol exposes certain system details as plain text
Low
CVE-2017-15709
was published
for
org.apache.activemq:activemq-openwire-generator
(Maven)
May 13, 2022
Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten Password
Low
CVE-2015-3189
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 13, 2022
Incorrect Default Permissions in Apache Commons FileUpload
Low
CVE-2013-0248
was published
for
commons-fileupload:commons-fileupload
(Maven)
May 5, 2022
Jenkins allows attackers to obtain the master cryptographic key
Low
CVE-2013-0158
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 5, 2022
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2012-0324
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 4, 2022
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2012-0325
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 4, 2022
Cross-site scripting in Apache ActiveMQ
Low
CVE-2010-0684
was published
for
org.apache.activemq:activemq-parent
(Maven)
May 2, 2022
Apache Tomcat information disclosure vulnerability
Low
CVE-2008-4308
was published
for
org.apache.tomcat:tomcat
(Maven)
May 2, 2022
Alkacon OpenCMS XSS via searchfilter parameter in system/workplace/admin/workplace/sessions.jsp
Low
CVE-2008-1753
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCMS XSS via searchfilter or listSearchFilter parameter
Low
CVE-2008-1510
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon Open CMS XSS via Logfile Viewer Settings function
Low
CVE-2008-1300
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCMS XSS via file tree navigation in system/workplace/views/explorer/tree_files.jsp
Low
CVE-2008-1045
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Apache Tomcat Path Traversal Vulnerability
Low
CVE-2007-5461
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Apache Tomcat vulnerable to Cross-site Scripting
Low
CVE-2007-2450
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Apache Tomcat XSS In Accept-Language Headers
Low
CVE-2007-1358
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Alkacon OpenCms XSS via unsanitized message body
Low
CVE-2006-3933
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCms XSS via query parameter in a search action
Low
CVE-2006-2571
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API