GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,780
Erlang
36
GitHub Actions
29
Go
2,344
Maven
5,000+
npm
3,973
NuGet
719
pip
3,770
Pub
12
RubyGems
923
Rust
978
Swift
38
Unreviewed advisories
All unreviewed
5,000+
282 advisories
Filter by severity
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5...
Moderate
Unreviewed
CVE-2016-0772
was published
May 14, 2022
Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream...
Moderate
Unreviewed
CVE-2018-6794
was published
May 14, 2022
Agent-to-controller security bypass in Jenkins BMC Compuware ISPW Operations plugin
Moderate
CVE-2022-36899
was published
for
com.compuware.jenkins:compuware-ispw-operations
(Maven)
Jul 28, 2022
A vulnerability in the detection engine of Cisco Firepower System Software could allow an...
Moderate
Unreviewed
CVE-2018-0138
was published
May 13, 2022
A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for...
Moderate
Unreviewed
CVE-2018-0250
was published
May 13, 2022
A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an...
High
Unreviewed
CVE-2018-0383
was published
May 13, 2022
A vulnerability in the detection engine of Cisco Firepower System Software could allow an...
Moderate
Unreviewed
CVE-2018-0254
was published
May 13, 2022
A vulnerability in the detection engine of Cisco Firepower Threat Defense software could allow an...
Moderate
Unreviewed
CVE-2018-0297
was published
May 13, 2022
A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could...
Moderate
Unreviewed
CVE-2018-0333
was published
May 13, 2022
A vulnerability in the detection engine of Cisco Firepower System Software could allow an...
Moderate
Unreviewed
CVE-2018-0243
was published
May 13, 2022
A vulnerability in the detection engine of Cisco Firepower System Software could allow an...
Moderate
Unreviewed
CVE-2018-0244
was published
May 13, 2022
A vulnerability in the web UI of Cisco TelePresence Server Software could allow an...
Moderate
Unreviewed
CVE-2018-0326
was published
May 13, 2022
A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an...
Moderate
Unreviewed
CVE-2018-0384
was published
May 13, 2022
A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD)...
High
Unreviewed
CVE-2019-1669
was published
May 13, 2022
Content-Security-Policy protection for user content disabled by Jenkins ScreenRecorder Plugin
High
CVE-2022-43433
was published
for
io.jenkins.plugins:screenrecorder
(Maven)
Oct 19, 2022
Content-Security-Policy protection for user content can be disabled in Jenkins 360 FireLine Plugin
High
CVE-2022-43435
was published
for
org.jenkins-ci.plugins.plugin:fireline
(Maven)
Oct 19, 2022
Sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin and Pipeline: Deprecated Groovy Libraries Plugin
High
CVE-2022-43405
was published
for
io.jenkins.plugins:pipeline-groovy-lib
(Maven)
Oct 19, 2022
Content-Security-Policy protection for user content disabled by Jenkins XFramium Builder Plugin
High
CVE-2022-43432
was published
for
org.jenkins-ci.plugins:xframium
(Maven)
Oct 19, 2022
Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy Plugin
High
CVE-2022-43404
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
Oct 19, 2022
Sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin
High
CVE-2022-43406
was published
for
io.jenkins.plugins:pipeline-groovy-lib
(Maven)
Oct 19, 2022
Script security sandbox bypass in Jenkins Email Extension Plugin
Critical
CVE-2019-1003032
was published
for
org.jenkins-ci.plugins:email-ext
(Maven)
May 13, 2022
Agent-to-controller security bypass in Jenkins xUnit Plugin
Moderate
CVE-2022-34181
was published
for
org.jenkins-ci.plugins:xunit
(Maven)
Jun 24, 2022
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access...
Critical
Unreviewed
CVE-2021-32835
was published
May 24, 2022
A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings...
Moderate
Unreviewed
CVE-2021-1517
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API