GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
5,926 advisories
Filter by severity
Jenkins Testsigma Test Plan vulnerability exposes API keys via job configuration form
Low
CVE-2025-53661
was published
for
io.jenkins.plugins:testsigma
(Maven)
Jul 9, 2025
Jenkins Nouvola DiveCloud Plugin vulnerability stores unencrypted credentials
Moderate
CVE-2025-53670
was published
for
org.jenkins-ci.plugins:nouvola-divecloud
(Maven)
Jul 9, 2025
Jenkins Dead Man's Snitch Plugin vulnerability does not mask tokens
Moderate
CVE-2025-53667
was published
for
org.jenkins-ci.plugins:deadmanssnitch
(Maven)
Jul 9, 2025
Jenkins Applitools Eyes Plugin vulnerable to XSS through its Build page
High
CVE-2025-53658
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Jenkins Dead Man's Snitch Plugin vulnerability stores tokens in plain text
Moderate
CVE-2025-53666
was published
for
org.jenkins-ci.plugins:deadmanssnitch
(Maven)
Jul 9, 2025
Jenkins QMetry Test Management Plugin stores unencrypted API keys
Moderate
CVE-2025-53659
was published
for
org.jenkins-ci.plugins:qmetry-test-management
(Maven)
Jul 9, 2025
Jenkins VAddy Plugin vulnerability exposes unencrypted keys to certain authenticated users
Moderate
CVE-2025-53668
was published
for
org.jenkins-ci.plugins:vaddy-plugin
(Maven)
Jul 9, 2025
Jenkins VAddy Plugin vulnerability exposes plaintext keys on its job configuration form
Moderate
CVE-2025-53669
was published
for
org.jenkins-ci.plugins:vaddy-plugin
(Maven)
Jul 9, 2025
Jenkins Xooa Plugin vulnerability exposes unencrypted tokens to authenticated users
Moderate
CVE-2025-53676
was published
for
io.jenkins.plugins:xooa
(Maven)
Jul 9, 2025
Jenkins User1st uTester Plugin vulnerability exposes unencrypted token to authenticated users
Low
CVE-2025-53678
was published
for
io.jenkins.plugins:user1st-utester
(Maven)
Jul 9, 2025
Jenkins Warrior Framework Plugin vulnerability exposes unencrypted passwords to certain authenticated users
Moderate
CVE-2025-53675
was published
for
org.jenkins-ci.plugins:warrior
(Maven)
Jul 9, 2025
Jenkins Xooa Plugin vulnerability does not mask its Xooa Deployment Token
Moderate
CVE-2025-53677
was published
for
io.jenkins.plugins:xooa
(Maven)
Jul 9, 2025
Jenkins Applitools Eyes Plugin vulnerability does not mask API keys on its job configuration form
Moderate
CVE-2025-53743
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Jenkins Applitools Eyes Plugin vulnerability exposes unencrypted keys to certain authenticated users
Moderate
CVE-2025-53742
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Duplicate Advisory: Keycloak phishing attack via email verification step in first login flow
Moderate
GHSA-gj52-35xm-gxjh
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 10, 2025
•
withdrawn
Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector
Moderate
CVE-2025-52434
was published
for
org.apache.tomcat:tomcat-util
(Maven)
Jul 10, 2025
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
Moderate
CVE-2025-52520
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Jul 10, 2025
Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams
Moderate
CVE-2025-53506
was published
for
org.apache.tomcat:tomcat-coyote
(Maven)
Jul 10, 2025
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
Moderate
CVE-2025-53864
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Jul 11, 2025
Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
Moderate
CVE-2025-48924
was published
for
commons-lang:commons-lang
(Maven)
Jul 11, 2025
Apache Zeppelin exposes server resources to unauthenticated attackers
High
CVE-2024-41169
was published
for
org.apache.zeppelin:zeppelin-interpreter
(Maven)
Jul 12, 2025
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
High
CVE-2025-53689
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Jul 14, 2025
XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
Critical
CVE-2025-53835
was published
for
org.xwiki.rendering:xwiki-rendering-syntax-xhtml
(Maven)
Jul 14, 2025
XWiki Rendering is vulnerable to RCE attacks when processing nested macros
Critical
CVE-2025-53836
was published
for
org.xwiki.rendering:xwiki-rendering-transformation-macro
(Maven)
Jul 14, 2025
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
Moderate
CVE-2025-48795
was published
for
org.apache.cxf:cxf-core
(Maven)
Jul 15, 2025
ProTip!
Advisories are also available from the
GraphQL API