GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
624 advisories
Filter by severity
Stored XSS vulnerability in Code Coverage API Plugin
Moderate
CVE-2020-2106
was published
for
io.jenkins.plugins:code-coverage-api
(Maven)
May 24, 2022
Inbound TCP Agent Protocol/3 authentication bypass in Jenkins
High
CVE-2020-2099
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Non-constant time comparison of inbound TCP agent connection secret
Moderate
CVE-2020-2101
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Non-constant time HMAC comparison
Moderate
CVE-2020-2102
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Jenkins Diagnostic page exposed session cookies
Moderate
CVE-2020-2103
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Jenkins vulnerable to UDP amplification reflection attack
Moderate
CVE-2020-2100
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Memory usage graphs accessible to anyone with Overall/Read
Moderate
CVE-2020-2104
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution
High
CVE-2020-2098
was published
for
org.jenkins-ci.plugins:sounds
(Maven)
May 24, 2022
Reflected XSS vulnerability in Jenkins gitlab-hook Plugin
Moderate
CVE-2020-2096
was published
for
org.jenkins-ci.ruby-plugins:gitlab-hook
(Maven)
May 24, 2022
Redgate SQL Change Automation Plugin stored credentials in plain text
Moderate
CVE-2020-2095
was published
for
com.redgate.plugins.redgatesqlci:redgate-sql-ci
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Robot Framework Plugin
High
CVE-2020-2092
was published
for
org.jenkins-ci.plugins:robot
(Maven)
May 24, 2022
Missing permission checks in Jenkins Sounds Plugin allow OS command execution
High
CVE-2020-2097
was published
for
org.jenkins-ci.plugins:sounds
(Maven)
May 24, 2022
Missing permission checks in Health Advisor by CloudBees Plugin
Moderate
CVE-2020-2094
was published
for
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Amazon EC2 Plugin
Low
CVE-2020-2090
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
Missing permission checks in Jenkins Amazon EC2 Plugin
Moderate
CVE-2020-2091
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
CSRF vulnerability in Health Advisor by CloudBees Plugin
Moderate
CVE-2020-2093
was published
for
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
(Maven)
May 24, 2022
Cross-Site Request Forgery in Jenkins Autocomplete Parameter Plugin
High
CVE-2022-30969
was published
for
org.jenkins-ci.plugins:autocomplete-parameter
(Maven)
May 18, 2022
XML External Entity Reference in Jenkins Storable Configs Plugin
High
CVE-2022-30971
was published
for
org.jvnet.hudson.plugins:storable-configs-plugin
(Maven)
May 18, 2022
Cross-site Scripting in Jenkins Autocomplete Parameter Plugin
High
CVE-2022-30970
was published
for
org.jenkins-ci.plugins:autocomplete-parameter
(Maven)
May 18, 2022
Cross Site Request Forgery in Jenkins Storable Configs Plugin
High
CVE-2022-30972
was published
for
org.jvnet.hudson.plugins:storable-configs-plugin
(Maven)
May 18, 2022
Missing permission check in Jenkins Blue Ocean Plugin
Moderate
CVE-2022-30954
was published
for
io.jenkins.blueocean:blueocean-parent
(Maven)
May 18, 2022
Cross-site Scripting in Jenkins Global Variable String Parameter Plugin
High
CVE-2022-30962
was published
for
org.jenkins-ci.plugins:global-variable-string-parameter
(Maven)
May 18, 2022
Cross site scripting in Jenkins Selection tasks Plugin
High
CVE-2022-30967
was published
for
org.jvnet.hudson.plugins:selection-tasks-plugin
(Maven)
May 18, 2022
Cross-site Scripting in Jenkins Multiselect parameter Plugin
High
CVE-2022-30964
was published
for
io.jenkins.plugins:multiselect-parameter
(Maven)
May 18, 2022
Stored Cross-site Scripting vulnerabilities in Jenkins promoted Builds (Simple) plugin providing additional parameter types
High
CVE-2022-30965
was published
for
org.jenkins-ci.plugins:promoted-builds-simple
(Maven)
May 18, 2022
ProTip!
Advisories are also available from the
GraphQL API