GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,494
Maven
5,000+
npm
4,129
NuGet
735
pip
3,944
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
526 advisories
Filter by severity
OpenStack Keystone Insufficient token expiration
High
CVE-2012-5563
was published
for
keystone
(pip)
May 17, 2022
Publify exposes article metadata
Moderate
CVE-2022-1553
was published
for
publify_core
(RubyGems)
May 17, 2022
Publify Incorrect Authorization
Moderate
CVE-2022-0574
was published
for
publify_core
(RubyGems)
May 17, 2022
Incorrect Authorization in Jenkins Core
Moderate
CVE-2016-3722
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Incorrect Authorization in Jenkins
Moderate
CVE-2018-1999047
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Cloud Foundry UAA accepts refresh token as access token on admin endpoints
High
CVE-2018-11047
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 13, 2022
Improper authorization vulnerability in Jenkins Mesos Plugin
Moderate
CVE-2018-1000420
was published
for
org.jenkins-ci.plugins:mesos
(Maven)
May 13, 2022
Jenkins Black Duck Hub Plugin allowed any user with Overall/Read to read and write its configuration
High
CVE-2018-1000197
was published
for
com.blackducksoftware.integration:blackduck-hub
(Maven)
May 13, 2022
Jenkins vSphere Plugin incorrect authorization vulnerability
Moderate
CVE-2018-1000152
was published
for
org.jenkins-ci.plugins:vsphere-cloud
(Maven)
May 13, 2022
Jenkins Subversion Plugin Incorrect Authorization vulnerability
Moderate
CVE-2018-1000111
was published
for
org.jenkins-ci.plugins:subversion
(Maven)
May 13, 2022
Incorrect Authorization in Jenkins Mercurial Plugin
Moderate
CVE-2018-1000112
was published
for
org.jenkins-ci.plugins:mercurial
(Maven)
May 13, 2022
Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes
Moderate
CVE-2018-1000114
was published
for
org.jenkins-ci.plugins:promoted-builds
(Maven)
May 13, 2022
Jenkins Google Play Android Publisher Plugin allows attacker to obtain credential IDs
Moderate
CVE-2018-1000109
was published
for
org.jenkins-ci.plugins:google-play-android-publisher
(Maven)
May 13, 2022
Incorrect Authorization in Jenkins Gerrit Trigger Plugin
Moderate
CVE-2018-1000105
was published
for
com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger
(Maven)
May 13, 2022
Incorrect Authorization in Jenkins Gerrit Trigger Plugin
Moderate
CVE-2018-1000106
was published
for
com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger
(Maven)
May 13, 2022
Incorrect Authorization in Jenkins Git Plugin
Moderate
CVE-2018-1000110
was published
for
org.jenkins-ci.plugins:git
(Maven)
May 13, 2022
Drupal editor module incorrectly checks access to inline private files
High
CVE-2017-6377
was published
for
drupal/core
(Composer)
May 13, 2022
Incorrect Authorization in Undertow
Moderate
CVE-2017-12196
was published
for
io.undertow:undertow-core
(Maven)
May 13, 2022
Jenkins Jira Plugin Incorrect Authorization vulnerability
Moderate
CVE-2018-1000412
was published
for
org.jenkins-ci.plugins:jira
(Maven)
May 13, 2022
Jenkins HipChat Plugin allows credential capture due to incorrect authorization
High
CVE-2018-1000418
was published
for
org.jvnet.hudson.plugins:hipchat
(Maven)
May 13, 2022
Apache Geode vulnerable to Incorrect Authorization
High
CVE-2017-15695
was published
for
org.apache.geode:geode-core
(Maven)
May 13, 2022
Incorrect Authorization in Jenkins Core
Moderate
CVE-2017-2611
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Moodle does not properly restrict comment capabilities
Moderate
CVE-2011-4297
was published
for
moodle/moodle
(Composer)
May 13, 2022
Incorrect Authorization in Jenkins
Moderate
CVE-2017-2599
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
OpenStack Identity service (keystone) Incorrect Authorization
High
CVE-2017-2673
was published
for
keystone
(pip)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API