GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
635 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation in Apache Sling
Moderate
CVE-2015-2944
was published
for
org.apache.sling:org.apache.sling.api
(Maven)
May 13, 2022
Pivotal Cloud Foundry UAA XSS on UAA OpenID Connect check session iframe endpoint
Moderate
CVE-2018-1190
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 13, 2022
Improper Neutralization of Input During Web Page Generation in Apache CXF
Moderate
CVE-2016-6812
was published
for
org.apache.cxf:cxf-core
(Maven)
May 13, 2022
Improper Neutralization of Input During Web Page Generation in Apache Hadoop
Moderate
CVE-2017-3161
was published
for
org.apache.hadoop:hadoop-client
(Maven)
May 13, 2022
Bootstrap vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2018-14040
was published
for
bootstrap
(RubyGems)
May 13, 2022
Rundeck Community Edition vulnerable to Cross-site Scripting
Moderate
CVE-2019-6804
was published
for
org.rundeck:rundeck
(Maven)
May 13, 2022
Cross-site Scripting in Jenkins
Moderate
CVE-2017-2601
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Cross-site Scripting in Apache DeltaSpike
Moderate
CVE-2017-17837
was published
for
org.apache.deltaspike.modules:jsf-module-project
(Maven)
May 13, 2022
Cross-site scripting vulnerability exists in Jenkins and Stapler Plugin
Moderate
CVE-2018-1999007
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Improper Neutralization of Input During Web Page Generation in Jenkins
Moderate
CVE-2019-1003050
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Improper Neutralization of Input During Web Page Generation in Jenkins
Moderate
CVE-2018-1999005
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Jenkins subject to Cross-site Scripting
Moderate
CVE-2013-0328
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 5, 2022
Improper Neutralization of Input During Web Page Generation in Spring Framework
Moderate
CVE-2013-6430
was published
for
org.springframework:spring-web
(Maven)
May 5, 2022
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
Moderate
CVE-2011-0013
was published
for
org.apache.tomcat:tomcat
(Maven)
May 3, 2022
Cross-site Scripting in in JRuby
Moderate
CVE-2010-1330
was published
for
org.jruby:jruby-core
(Maven)
May 2, 2022
Cross-site scripting in Apache Tomcat
Moderate
CVE-2009-0781
was published
for
org.apache.tomcat:tomcat
(Maven)
May 2, 2022
Apache Geronimo Application Server multiple cross-site scripting (XSS) vulnerabilities
Moderate
CVE-2009-0038
was published
for
org.apache.geronimo.plugins:console
(Maven)
May 2, 2022
Apache Jackrabbit contains Cross-site Scripting
Moderate
CVE-2009-0026
was published
for
org.apache.jackrabbit:jackrabbit
(Maven)
May 2, 2022
Apache Struts Cross-site Scripting vulnerability
Moderate
CVE-2008-2025
was published
for
struts:struts
(Maven)
May 1, 2022
Apache Tomcat Cross-site scripting (XSS) vulnerability
Moderate
CVE-2008-1947
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 1, 2022
Cross-site scripting (XSS) vulnerability in Sun Java Server Faces (JSF)
Moderate
CVE-2008-1285
was published
for
com.sun.faces:jsf-api
(Maven)
May 1, 2022
Apache Tomcat Cross-site scripting (XSS) vulnerability
Moderate
CVE-2008-1232
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Apache Struts Dojo Plugin XSS Vulnerability
Moderate
CVE-2007-6726
was published
for
org.apache.struts:struts2-dojo-plugin
(Maven)
May 1, 2022
Mortbay Jetty vulnerable to Cross-site scripting
Moderate
CVE-2007-5613
was published
for
org.mortbay.jetty:jetty
(Maven)
May 1, 2022
Apache Tomcat Vulnerable to Cross-Site Scripting
Moderate
CVE-2007-1355
was published
for
org.apache.tomcat:jsp-api
(Maven)
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API