GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,163
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
21,599 advisories
Filter by severity
MongoDB Tools Improper Certificate Validation vulnerability
Moderate
CVE-2020-7924
was published
for
github.com/mongodb/mongo-tools
(Go)
May 24, 2022
Wikimedia Parsoid vulnerable to Cross-site Scripting (XSS)
Moderate
CVE-2021-30458
was published
for
wikimedia/parsoid
(Composer)
May 24, 2022
Reflected XSS vulnerability in Jenkins Micro Focus Application Automation Tools Plugin
High
CVE-2021-22510
was published
for
org.jenkins-ci.plugins:hp-application-automation-tools-plugin
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Micro Focus Application Automation Tools Plugin
Moderate
CVE-2021-22512
was published
for
org.jenkins-ci.plugins:hp-application-automation-tools-plugin
(Maven)
May 24, 2022
SSL/TLS certificate validation unconditionally disabled by Jenkins Micro Focus Application Automation Tools Plugin
Moderate
CVE-2021-22511
was published
for
org.jenkins-ci.plugins:hp-application-automation-tools-plugin
(Maven)
May 24, 2022
Missing permission checks in Micro Focus Application Automation Tools Plugin
Moderate
CVE-2021-22513
was published
for
org.jenkins-ci.plugins:hp-application-automation-tools-plugin
(Maven)
May 24, 2022
subrion CMS Cross Site Scripting (XSS) vulnerability
Moderate
CVE-2020-23761
was published
for
intelliants/subrion
(Composer)
May 24, 2022
Lack of type validation in agent related REST API in Jenkins
Moderate
CVE-2021-21639
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins promoted builds Plugin
Moderate
CVE-2021-21641
was published
for
org.jenkins-ci.plugins:promoted-builds
(Maven)
May 24, 2022
View name validation bypass in Jenkins
Moderate
CVE-2021-21640
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Docsify vulnerable to cross-site scripting due to mishandled encoding
Moderate
CVE-2021-30074
was published
for
docsify
(npm)
May 24, 2022
Passwords stored in plain text by Jenkins Jabber (XMPP) notifier and control Plugin
Moderate
CVE-2021-21634
was published
for
org.jvnet.hudson.plugins:jabber
(Maven)
May 24, 2022
Missing permission checks in Jenkins OWASP Dependency-Track Plugin allow capturing credentials
Moderate
CVE-2021-21632
was published
for
org.jenkins-ci.plugins:dependency-track
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Team Foundation Server Plugin allow capturing credentials
High
CVE-2021-21638
was published
for
org.jenkins-ci.plugins:tfs
(Maven)
May 24, 2022
Missing permission check in Jenkins Team Foundation Server Plugin allows enumerating credentials IDs
Moderate
CVE-2021-21636
was published
for
org.jenkins-ci.plugins:tfs
(Maven)
May 24, 2022
Missing permission check in Jenkins Team Foundation Server Plugin allow capturing credentials
Moderate
CVE-2021-21637
was published
for
org.jenkins-ci.plugins:tfs
(Maven)
May 24, 2022
Missing permission check in Jenkins Cloud Statistics Plugin
Moderate
CVE-2021-21631
was published
for
org.jenkins-ci.plugins:cloud-stats
(Maven)
May 24, 2022
CSRF vulnerability and in Jenkins OWASP Dependency-Track Plugin allow capturing credentials
High
CVE-2021-21633
was published
for
org.jenkins-ci.plugins:dependency-track
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins REST List Parameter Plugin
Moderate
CVE-2021-21635
was published
for
io.jenkins.plugins:rest-list-parameter
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Extra Columns Plugin
Moderate
CVE-2021-21630
was published
for
org.jenkins-ci.plugins:extra-columns
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Build With Parameters Plugin
High
CVE-2021-21629
was published
for
org.jenkins-ci.plugins:build-with-parameters
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Build With Parameters Plugin
Moderate
CVE-2021-21628
was published
for
org.jenkins-ci.plugins:build-with-parameters
(Maven)
May 24, 2022
Craft CMS Cross-site Scripting Vulnerability
Moderate
CVE-2020-19626
was published
for
craftcms/cms
(Composer)
May 24, 2022
Reflected XSS in Zen Cart before 1.5.7a
Moderate
CVE-2020-6578
was published
for
zencart/zencart
(Composer)
May 24, 2022
Concrete CMS Cross-site Scripting via Survey Blocks
Moderate
CVE-2021-28145
was published
for
concrete5/concrete5
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API