GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,932 advisories
Filter by severity
SnakeYaml Constructor Deserialization Remote Code Execution
High
CVE-2022-1471
was published
for
org.yaml:snakeyaml
(Maven)
Dec 12, 2022
Protobuf Java vulnerable to Uncontrolled Resource Consumption
High
CVE-2022-3510
was published
for
com.google.protobuf:protobuf-java
(Maven)
Dec 12, 2022
Protobuf Java vulnerable to Uncontrolled Resource Consumption
High
CVE-2022-3509
was published
for
com.google.protobuf:protobuf-java
(Maven)
Dec 12, 2022
Stored XSS vulnerability in Jenkins Checkmarx Plugin
High
CVE-2022-46684
was published
for
com.checkmarx.jenkins:checkmarx
(Maven)
Dec 12, 2022
Cross-site Scripting in Jenkins Spring Config Plugin
High
CVE-2022-46687
was published
for
io.jenkins.plugins:spring-config
(Maven)
Dec 12, 2022
Jenkins Plot Plugin XML External Entity Reference vulnerability
High
CVE-2022-46682
was published
for
org.jenkins-ci.plugins:plot
(Maven)
Dec 12, 2022
Jenkins Custom Build Properties Plugin vulnerable to Cross-site Scripting
High
CVE-2022-46686
was published
for
io.jenkins.plugins:custom-build-properties
(Maven)
Dec 12, 2022
Spring Boot Admins integrated notifier support allows arbitrary code execution
High
CVE-2022-46166
was published
for
de.codecentric:spring-boot-admin
(Maven)
Dec 9, 2022
Yauaa vulnerable to ArrayIndexOutOfBoundsException triggered by a crafted Sec-Ch-Ua-Full-Version-List
High
CVE-2022-23496
was published
for
nl.basjes.parse.useragent:yauaa
(Maven)
Dec 8, 2022
Quarkus CORS filter allows simple GET and POST requests with an invalid Origin to proceed
High
CVE-2022-4147
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Dec 6, 2022
TERASOLUNA Server Framework vulnerable to ClassLoader manipulation
High
CVE-2022-43484
was published
for
org.terasoluna.gfw:terasoluna-gfw-common
(Maven)
Dec 5, 2022
HTSJDK is vulnerable to exposure of resource(s) to the wrong sphere
High
CVE-2022-21126
was published
for
com.github.samtools:htsjdk
(Maven)
Nov 29, 2022
FusionAuth vulnerable to directory traversal attack
High
CVE-2022-45921
was published
for
io.fusionauth:fusionauth-java-client
(Maven)
Nov 28, 2022
Apache Dolphin Scheduler has insufficiently protected credentials
High
CVE-2022-26885
was published
for
org.apache.dolphinscheduler:dolphinscheduler-common
(Maven)
Nov 24, 2022
Password exposure in H2 Database
High
CVE-2022-45868
was published
for
com.h2database:h2
(Maven)
Nov 23, 2022
Creation of new database tables through login form on PostgreSQL
High
CVE-2022-41932
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Nov 21, 2022
Cross-Site Request Forgery (CSRF) allowing to delete or rename tags
High
CVE-2022-41927
was published
for
org.xwiki.platform:xwiki-platform-tag-ui
(Maven)
Nov 21, 2022
Cross-site Scripting in Apache Hama
High
CVE-2022-45470
was published
for
org.apache.hama:hama-core
(Maven)
Nov 21, 2022
TestNG is vulnerable to Path Traversal
High
CVE-2022-4065
was published
for
org.testng:testng
(Maven)
Nov 19, 2022
XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)
High
CVE-2022-43183
was published
for
com.xuxueli:xxl-job-core
(Maven)
Nov 17, 2022
Jenkins Config Rotator Plugin vulnerable to path traversal
High
CVE-2022-45388
was published
for
org.jenkins-ci.main:config-rotator
(Maven)
Nov 16, 2022
Jenkins Associated Files Plugin vulnerable to cross-site scripting (XSS)
High
CVE-2022-45401
was published
for
org.jenkins-ci.main:associated-files-plugin
(Maven)
Nov 16, 2022
XXE vulnerability in Jenkins JAPEX Plugin
High
CVE-2022-45400
was published
for
org.jvnet.hudson.plugins:japex
(Maven)
Nov 16, 2022
Jenkins BART Plugin vulnerable to cross-site scripting (XSS)
High
CVE-2022-45387
was published
for
org.jenkins-ci.plugins:bart
(Maven)
Nov 16, 2022
Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions
High
CVE-2022-45379
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Nov 16, 2022
ProTip!
Advisories are also available from the
GraphQL API