GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,935 advisories
Filter by severity
ballcat-codegen template engine remote code execution injection
High
CVE-2022-24881
was published
for
com.hccake:ballcat-codegen
(Maven)
Apr 27, 2022
OutOfMemory Exception by specifically crafted processing instruction in NekoHtml Parser
High
CVE-2022-29546
was published
for
net.sourceforge.htmlunit:neko-htmlunit
(Maven)
Apr 26, 2022
JBoss AS may expose root content if excluded-contexts list is mismatched
High
CVE-2012-1094
was published
for
org.jboss.as:jboss-as-server
(Maven)
Apr 23, 2022
Hash collision attack vulnerability in Jenkins
High
CVE-2012-0785
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Apr 23, 2022
Unrestricted Upload of File with Dangerous Type in Apache Struts2
High
CVE-2012-1592
was published
for
org.apache.struts:struts2-core
(Maven)
Apr 23, 2022
Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP Access
High
CVE-2012-4438
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Apr 23, 2022
Hadoop symlink vulnerability
High
CVE-2012-2945
was published
for
org.apache.hadoop:hadoop-main
(Maven)
Apr 23, 2022
Denial of service in HtmlUnit-Neko
High
CVE-2022-28366
was published
for
net.sourceforge.htmlunit:neko-htmlunit
(Maven)
Apr 23, 2022
Cross Site Request Forgery in Mingsoft MCMS
High
CVE-2022-27340
was published
for
net.mingsoft:ms-mcms
(Maven)
Apr 23, 2022
Improper Input Validation in GeoServer
High
CVE-2022-24847
was published
for
org.geoserver:gs-main
(Maven)
Apr 22, 2022
XML External Entity Reference in detekt
High
CVE-2022-0272
was published
for
io.gitlab.arturbosch.detekt:detekt-core
(Maven)
Apr 22, 2022
Selenium Server (Grid) CSRF
High
CVE-2022-28108
was published
for
org.seleniumhq.selenium:selenium-grid
(Maven)
Apr 20, 2022
Improper handling of case sensitivity in Spring Framework
High
CVE-2022-22968
was published
for
org.springframework:spring-context
(Maven)
Apr 15, 2022
Stored Cross-site Scripting vulnerability in Jenkins Gerrit Trigger Plugin
High
CVE-2022-29039
was published
for
com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger
(Maven)
Apr 13, 2022
Untrusted users can modify some Pipeline libraries in Jenkins Pipeline: Deprecated Groovy Libraries Plugin
High
CVE-2022-29047
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps-global-lib
(Maven)
Apr 13, 2022
Stored Cross-site Scripting vulnerability in Jenkins Promoted Builds Plugin
High
CVE-2022-29045
was published
for
org.jenkins-ci.plugins:promoted-builds
(Maven)
Apr 13, 2022
CSRF vulnerability in Jenkins Publish Over FTP Plugin
High
CVE-2022-29050
was published
for
org.jenkins-ci.plugins:publish-over-ftp
(Maven)
Apr 13, 2022
Promotion names in Jenkins promoted builds Plugin are not validated when using Job DSL
High
CVE-2022-29049
was published
for
org.jenkins-ci.plugins:promoted-builds
(Maven)
Apr 13, 2022
SQL Injection in elide-datastore-aggregation
High
CVE-2022-24827
was published
for
com.yahoo.elide:elide-datastore-aggregation
(Maven)
Apr 8, 2022
SQL injection in net.mingsoft:ms-mcms
High
CVE-2022-26585
was published
for
net.mingsoft:ms-mcms
(Maven)
Apr 6, 2022
Logic error in Apache Pinot
High
CVE-2022-23974
was published
for
org.apache.pinot:pinot
(Maven)
Apr 6, 2022
Path Traversal in Caucho Resin
High
CVE-2021-44138
was published
for
com.caucho:resin
(Maven)
Apr 5, 2022
Keycloak insufficient session expiration
High
CVE-2021-3461
was published
for
org.keycloak:keycloak-parent
(Maven)
Apr 3, 2022
Uncontrolled Resource Consumption in Apache DolphinScheduler
High
CVE-2022-25598
was published
for
apache-dolphinscheduler
(Maven)
Mar 31, 2022
XML External Entity Reference vulnerability in Jenkins Pipeline: Phoenix AutoTest Plugin
High
CVE-2022-28155
was published
for
com.surenpi.jenkins:phoenix-autotest
(Maven)
Mar 30, 2022
ProTip!
Advisories are also available from the
GraphQL API