GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
23,904 advisories
Filter by severity
Jenkins BART Plugin vulnerable to cross-site scripting (XSS)
High
CVE-2022-45387
was published
for
org.jenkins-ci.plugins:bart
(Maven)
Nov 16, 2022
Cross-Site Request Forgery in Jenkins Delete log Plugin
Moderate
CVE-2022-45393
was published
for
org.jenkins-ci.plugins:delete-log-plugin
(Maven)
Nov 16, 2022
Jenkins Config Rotator Plugin vulnerable to path traversal
High
CVE-2022-45388
was published
for
org.jenkins-ci.main:config-rotator
(Maven)
Nov 16, 2022
Incorrect permission checks in Jenkins Support Core Plugin
Moderate
CVE-2022-45383
was published
for
org.jenkins-ci.plugins:support-core
(Maven)
Nov 16, 2022
Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion
High
CVE-2022-45380
was published
for
org.jenkins-ci.plugins:junit
(Maven)
Nov 16, 2022
Arbitrary file read vulnerability in Jenkins Pipeline Utility Steps Plugin
High
CVE-2022-45381
was published
for
org.jenkins-ci.plugins:pipeline-utility-steps
(Maven)
Nov 16, 2022
Cross-site Scripting in Jenkins Naginator Plugin
Moderate
CVE-2022-45382
was published
for
org.jenkins-ci.plugins:naginator
(Maven)
Nov 16, 2022
Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions
High
CVE-2022-45379
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Nov 16, 2022
SSL/TLS certificate validation unconditionally disabled by Jenkins NS-ND Integration Performance Publisher Plugin
Moderate
CVE-2022-38666
was published
for
org.jenkins-ci.main:cavisson-ns-nd-integration
(Maven)
Nov 16, 2022
PHPServerMon PRNG has Insufficient Entropy
Moderate
CVE-2021-4241
was published
for
phpservermon/phpservermon
(Composer)
Nov 16, 2022
Insufficient Entropy in PHPServerMon PRNG
Moderate
CVE-2021-4240
was published
for
phpservermon/phpservermon
(Composer)
Nov 16, 2022
Missing Authorization in HashiCorp Consul
High
CVE-2022-3920
was published
for
github.com/hashicorp/consul
(Go)
Nov 16, 2022
Cross-Site Request Forgery in feehi/feehicms
Moderate
CVE-2022-4014
was published
for
feehi/feehicms
(Composer)
Nov 16, 2022
Unsafe deserialization in Apache MINA SSHD
Critical
CVE-2022-45047
was published
for
org.apache.sshd:sshd-common
(Maven)
Nov 16, 2022
Cross Site Scripting vulnerability in wsgidav when directory browsing is enabled
High
CVE-2022-41905
was published
for
wsgidav
(pip)
Nov 16, 2022
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
High
CVE-2020-7731
was published
for
github.com/russellhaering/gosaml2
(Go)
Nov 15, 2022
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
High
CVE-2022-40308
was published
for
org.apache.archiva:archiva-common
(Maven)
Nov 15, 2022
Apache Archiva subject to arbitrary directory deletion by users.
Moderate
CVE-2022-40309
was published
for
org.apache.archiva:archiva-common
(Maven)
Nov 15, 2022
Concrete CMS vulnerable to Reflected Cross-site Scripting via image manipulation library
Moderate
CVE-2022-43694
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
Concrete CMS vulnerable to Reflected Cross-site Scripting
Moderate
CVE-2022-43692
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
rdiffweb vulnerable to Insufficient Session Expiration
High
CVE-2022-3362
was published
for
rdiffweb
(pip)
Nov 15, 2022
Concrete CMS vulnerable to Cross-site Scripting via multilingual report
Moderate
CVE-2022-43967
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
Concrete CMS vulnerable to Cross-site Scripting
Moderate
CVE-2022-43688
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
Concrete CMS vulnerable to Reflected Cross-Site Scripting via dashboard icons
Moderate
CVE-2022-43968
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
Concrete CMS vulnerable to Cleartext Transmission of Sensitive Information
Moderate
CVE-2022-43691
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
ProTip!
Advisories are also available from the
GraphQL API