GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,411
Erlang
33
GitHub Actions
22
Go
2,146
Maven
5,000+
npm
3,808
NuGet
687
pip
3,481
Pub
12
RubyGems
897
Rust
899
Swift
38
Unreviewed advisories
All unreviewed
5,000+
21,438 advisories
Filter by severity
Missing permission checks in Jenkins Ansible Plugin allow enumerating credentials IDs
Moderate
CVE-2020-2310
was published
for
org.jenkins-ci.plugins:ansible
(Maven)
May 24, 2022
Missing permission check in Jenkins AWS Global Configuration Plugin allows replacing plugin configuration
Moderate
CVE-2020-2311
was published
for
io.jenkins.plugins:aws-global-configuration
(Maven)
May 24, 2022
Missing authorization in Jenkins Kubernetes Plugin
Moderate
CVE-2020-2309
was published
for
org.csanchez.jenkins.plugins:kubernetes
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Static Analysis Utilities Plugin
Moderate
CVE-2020-2316
was published
for
org.jvnet.hudson.plugins:analysis-core
(Maven)
May 24, 2022
Missing permission checks in Jenkins Azure Key Vault Plugin allow enumerating credentials IDs
Moderate
CVE-2020-2313
was published
for
org.jenkins-ci.plugins:azure-keyvault
(Maven)
May 24, 2022
Password written to the build log by Jenkins SQLPlus Script Runner Plugin
Moderate
CVE-2020-2312
was published
for
org.jenkins-ci.plugins:sqlplus-script-runner
(Maven)
May 24, 2022
Improper Authentication (empty password) in Jenkins Active Directory Plugin
Critical
CVE-2020-2300
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Subversion Plugin
Moderate
CVE-2020-2304
was published
for
org.jenkins-ci.plugins:subversion
(Maven)
May 24, 2022
Authentication cache in Active Directory Jenkins Plugin allows logging in with any password
Critical
CVE-2020-2301
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Mercurial Plugin
Moderate
CVE-2020-2305
was published
for
org.jenkins-ci.plugins:mercurial
(Maven)
May 24, 2022
Improper Authentication in Jenkins Active Directory Plugin
Critical
CVE-2020-2299
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 24, 2022
Missing permission check in Jenkins Active Directory Plugin allows accessing domain health check page
Moderate
CVE-2020-2302
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Active Directory Plugin
Moderate
CVE-2020-2303
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 24, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin
Moderate
CVE-2020-2307
was published
for
org.csanchez.jenkins.plugins:kubernetes
(Maven)
May 24, 2022
Missing Authorization in Jenkins Mercurial Plugin
Moderate
CVE-2020-2306
was published
for
org.jenkins-ci.plugins:mercurial
(Maven)
May 24, 2022
Bookstack Cross-site Scripting vulnerability
High
CVE-2020-26211
was published
for
ssddanbrown/bookstack
(Composer)
May 24, 2022
Uncontrolled Resource Consumption in WildFly
Moderate
CVE-2020-25689
was published
for
org.wildfly:wildfly-dist
(Maven)
May 24, 2022
aptdaemon Information Disclosure via Improper Input Validation in Transaction class
Moderate
CVE-2020-15703
was published
for
aptdaemon
(pip)
May 24, 2022
Gophish vulnerable to Server-Side Request Forgery
Moderate
CVE-2020-24710
was published
for
github.com/gophish/gophish
(Go)
May 24, 2022
Grafana XSS via a query alias for the ElasticSearch datasource
Moderate
CVE-2020-24303
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Duplicate Advisory: Unauthorized privilege escalation in Mod module
High
GHSA-q886-75m2-vff8
was published
for
red-discordbot
(pip)
May 24, 2022
•
withdrawn
YOURLS Stored Cross Site Scripting (XSS)
Moderate
CVE-2020-27388
was published
for
yourls/yourls
(Composer)
May 24, 2022
Out-of-bounds Read in Facebook Hermes
High
CVE-2020-1915
was published
for
hermes-engine
(npm)
May 24, 2022
fabric8-maven-plugin: insecure way to construct Yaml Object leading to remote code execution
High
CVE-2020-10721
was published
for
io.fabric8:fabric8-maven-plugin
(Maven)
May 24, 2022
Magento 2 Community Edition XSS Vulnerability
Moderate
CVE-2020-24408
was published
for
magento/community-edition
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API