GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,783
Erlang
36
GitHub Actions
29
Go
2,353
Maven
5,000+
npm
3,977
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
756 advisories
Filter by severity
Jenkins Build Failure Analyzer Plugin Cross-Site Request Forgery vulnerability
Moderate
CVE-2023-43502
was published
for
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
(Maven)
Sep 20, 2023
Jenkins Build Failure Analyzer Plugin Cross-Site Request Forgery vulnerability
Moderate
CVE-2023-43500
was published
for
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
(Maven)
Sep 20, 2023
Cross-Site Request Forgery (CSRF) in usememos/memos
High
CVE-2023-5036
was published
for
github.com/usememos/memos
(Go)
Sep 18, 2023
CSRF vulnerability in Jenkins AWS CodeCommit Trigger Plugin
Moderate
CVE-2023-41942
was published
for
org.jenkins-ci.plugins:aws-codecommit-trigger
(Maven)
Sep 6, 2023
CSRF vulnerability in Jenkins Frugal Testing Plugin
Low
CVE-2023-41946
was published
for
io.jenkins.plugins:frugal-testing
(Maven)
Sep 6, 2023
CSRF vulnerability in Jenkins Ivy Plugin
Moderate
CVE-2023-41938
was published
for
org.jenkins-ci.plugins:ivy
(Maven)
Sep 6, 2023
XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action
High
CVE-2023-40572
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Aug 23, 2023
Jenkins Fortify Plugin cross-site request forgery vulnerability
Moderate
CVE-2023-4301
was published
for
org.jenkins-ci.plugins:fortify
(Maven)
Aug 22, 2023
Wallabag user can reset data unintentionally
Moderate
CVE-2023-4454
was published
for
wallabag/wallabag
(Composer)
Aug 21, 2023
Wallabag user can delete own API client unintentionally
Moderate
CVE-2023-4455
was published
for
wallabag/wallabag
(Composer)
Aug 21, 2023
Duplicate Advisory: Wallabag user can reset data unintentionally
Moderate
GHSA-rwpg-4c4c-v3r4
was published
for
wallabag/wallabag
(Composer)
Aug 21, 2023
•
withdrawn
Duplicate Advisory: Wallabag user can delete own API client unintentionally
Moderate
GHSA-gvvx-fc6p-2h9x
was published
for
wallabag/wallabag
(Composer)
Aug 21, 2023
•
withdrawn
Jenkins Blue Ocean Plugin cross-site request forgery vulnerability
Moderate
CVE-2023-40341
was published
for
io.jenkins.blueocean:blueocean
(Maven)
Aug 16, 2023
Jenkins Favorite View Plugin cross-site request forgery vulnerability
Moderate
CVE-2023-40351
was published
for
org.jenkins-ci.plugins:favorite-view
(Maven)
Aug 16, 2023
Jenkins Folders Plugin cross-site request forgery vulnerability
High
CVE-2023-40336
was published
for
org.jenkins-ci.plugins:cloudbees-folder
(Maven)
Aug 16, 2023
Jenkins Folders Plugin cross-site request forgery vulnerability
Moderate
CVE-2023-40337
was published
for
org.jenkins-ci.plugins:cloudbees-folder
(Maven)
Aug 16, 2023
xuxueli xxl-job Cross-Site Request Forgery Vulnerability
High
CVE-2020-24922
was published
for
com.xuxueli:xxl-job
(Maven)
Aug 11, 2023
wger Workout Manager Cross-Site Request Forgery vulnerability
High
CVE-2023-38759
was published
for
wger
(pip)
Aug 8, 2023
Credential leakage in Jenkins Plug-in for ServiceNow
Moderate
CVE-2023-3414
was published
for
io.jenkins.plugins:servicenow-devops
(Maven)
Jul 26, 2023
CSRF vulnerability in GitLab Authentication Plugin
Moderate
CVE-2023-39153
was published
for
org.jenkins-ci.plugins:gitlab-oauth
(Maven)
Jul 26, 2023
CSRF vulnerability in Bazaar Plugin
Moderate
CVE-2023-39156
was published
for
org.jenkins-ci.plugins:bazaar
(Maven)
Jul 26, 2023
Cockpit CMS Cross-Site Request Forgery vulnerability
High
CVE-2023-37650
was published
for
cockpit-hq/cockpit
(Composer)
Jul 20, 2023
Jenkins Benchmark Evaluator Plugin vulnerable to cross-site request forgery
High
CVE-2023-37962
was published
for
io.jenkins.plugins:benchmark-evaluator
(Maven)
Jul 12, 2023
Jenkins ElasticBox CI Plugin vulnerable to cross-site request forgery
High
CVE-2023-37964
was published
for
org.jenkins-ci.plugins:elasticbox
(Maven)
Jul 12, 2023
Jenkins Sumologic Publisher Plugin vulnerable to cross-site request forgery
High
CVE-2023-37958
was published
for
org.jenkins-ci.plugins:sumologic-publisher
(Maven)
Jul 12, 2023
ProTip!
Advisories are also available from the
GraphQL API