GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,793
Erlang
36
GitHub Actions
29
Go
2,380
Maven
5,000+
npm
4,004
NuGet
720
pip
3,803
Pub
12
RubyGems
927
Rust
985
Swift
38
Unreviewed advisories
All unreviewed
5,000+
329 advisories
Filter by severity
Missing Authorization in Jenkins XP-Dev Plugin
Moderate
CVE-2022-45389
was published
for
com.cloudbees.jenkins.plugins:xpdev
(Maven)
Nov 16, 2022
Lack of authentication mechanism for webhook in CloudBees Docker Hub/Registry Notification Plugin
Moderate
CVE-2022-45385
was published
for
org.jenkins-ci.plugins:dockerhub-notification
(Maven)
Nov 16, 2022
Apache Archiva subject to arbitrary directory deletion by users.
Moderate
CVE-2022-40309
was published
for
org.apache.archiva:archiva-common
(Maven)
Nov 15, 2022
Apache Archiva vulnerable to Sensitive Information Disclosure via anonymous user
High
CVE-2022-40308
was published
for
org.apache.archiva:archiva-common
(Maven)
Nov 15, 2022
Jenkins Job Import Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins
Moderate
CVE-2022-43413
was published
for
org.jenkins-ci.plugins:job-import-plugin
(Maven)
Oct 19, 2022
Jenkins Compuware Strobe Measurement Plugin Missing Authorization vulnerability
Moderate
CVE-2022-43431
was published
for
com.compuware.jenkins:compuware-strobe-measurement
(Maven)
Oct 19, 2022
Jenkins Tuleap Git Branch Source Plugin allows unauthenticated attackers to trigger Tuleap projects whose configured repo matches attacker-specified value
Moderate
CVE-2022-43421
was published
for
org.jenkins-ci.plugins:tuleap-git-branch-source
(Maven)
Oct 19, 2022
Missing permission checks in Jenkins Katalon Plugin allow capturing credentials
Moderate
CVE-2022-43417
was published
for
org.jenkins-ci.plugins:katalon
(Maven)
Oct 19, 2022
Jenkins Compuware Topaz for Total Test Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins
Moderate
CVE-2022-43427
was published
for
com.compuware.jenkins:compuware-topaz-for-total-test
(Maven)
Oct 19, 2022
Liferay Portal Missing Authorization vulnerability
Moderate
CVE-2022-39975
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 23, 2022
Missing permission check in Jenkins build-publisher Plugin
Moderate
CVE-2022-41230
was published
for
org.jenkins-ci.plugins:build-publisher
(Maven)
Sep 22, 2022
Lack of authentication mechanism in Jenkins DotCi Plugin webhook
Moderate
CVE-2022-41238
was published
for
com.groupon.jenkins-ci.plugins:DotCi
(Maven)
Sep 22, 2022
CSRF vulnerability and mM
Moderate
CVE-2022-41246
was published
for
org.jenkins-ci.plugins:ws-execution-manager
(Maven)
Sep 22, 2022
Jenkins Rundeck Plugin Missing Authorization vulnerability
Moderate
CVE-2022-41233
was published
for
org.jenkins-ci.plugins:rundeck
(Maven)
Sep 22, 2022
Jenkins extreme-feedback Plugin vulnerable to Missing Authorization
Moderate
CVE-2022-41242
was published
for
org.jenkins-ci.plugins:extreme-feedback
(Maven)
Sep 22, 2022
Missing webhook endpoint authorization in Jenkins Rundeck Plugin
Moderate
CVE-2022-41234
was published
for
org.jenkins-ci.plugins:rundeck
(Maven)
Sep 22, 2022
Jenkins NS-ND Integration Performance Publisher Plugin vulnerable to Missing Authorization
Moderate
CVE-2022-41228
was published
for
io.jenkins.plugins:cavisson-ns-nd-integration
(Maven)
Sep 22, 2022
Missing permission checks in Jenkins CONS3RT Plugin allow enumerating credentials IDs
Moderate
CVE-2022-41252
was published
for
org.jenkins-ci.plugins:cons3rt
(Maven)
Sep 22, 2022
Missing permission checks in Jenkins CONS3RT Plugin allow capturing credentials
Moderate
CVE-2022-41254
was published
for
org.jenkins-ci.plugins:cons3rt
(Maven)
Sep 22, 2022
Jenkins Apprenda Plugin has Missing Authorization vulnerability
Moderate
CVE-2022-41251
was published
for
org.jenkins-ci.plugins:apprenda
(Maven)
Sep 22, 2022
Missing permission check in Jenkins SCM HttpClient Plugin allow capturing credentials
Moderate
CVE-2022-41250
was published
for
com.meowlomo.jenkins:scm-httpclient
(Maven)
Sep 22, 2022
XWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same reference
High
CVE-2022-31167
was published
for
org.xwiki.platform:xwiki-platform-security
(Maven)
Sep 20, 2022
XWiki Platform Web Templates vulnerable to Missing Authorization, Exposure of Private Personal Information to Unauthorized Actor
High
CVE-2022-36091
was published
for
org.xwiki.platform:xwiki-platform-web
(Maven)
Sep 16, 2022
Apache IoTDB grafana-connector contains an interface without authorization
High
CVE-2022-38370
was published
for
org.apache.iotdb:iotdb-grafana-connector
(Maven)
Sep 6, 2022
Jenkins HashiCorp Vault Plugin does not perform permission checks in several HTTP endpoints that perform Vault connection tests
Moderate
CVE-2022-36888
was published
for
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
(Maven)
Jul 28, 2022
ProTip!
Advisories are also available from the
GraphQL API