GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
210 advisories
Filter by severity
XML External Entity Reference in Jenkins Recipe Plugin
High
CVE-2022-34793
was published
for
org.jenkins-ci.plugins:recipe
(Maven)
Jul 1, 2022
OS command execution vulnerability in Perfecto Plugin
High
CVE-2020-2261
was published
for
io.jenkins.plugins:perfecto
(Maven)
May 24, 2022
Stored XSS vulnerability in ClearCase Release Plugin
High
CVE-2020-2270
was published
for
org.jvnet.hudson.plugins:clearcase-release
(Maven)
May 24, 2022
Stored XSS vulnerability in Description Column Plugin
High
CVE-2020-2266
was published
for
org.jenkins-ci.plugins:description-column-plugin
(Maven)
May 24, 2022
Stored XSS vulnerability in android-lint Plugin
High
CVE-2020-2262
was published
for
org.jvnet.hudson.plugins:android-lint
(Maven)
May 24, 2022
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
High
CVE-2020-2228
was published
for
org.jenkins-ci.plugins:gitlab-oauth
(Maven)
May 24, 2022
Stored XSS vulnerability in Radiator View Plugin
High
CVE-2020-2263
was published
for
org.jenkins-ci.plugins:radiatorviewplugin
(Maven)
May 24, 2022
Stored XSS vulnerability in chosen-views-tabbar Plugin
High
CVE-2020-2269
was published
for
org.jenkins-ci.plugins:chosen-views-tabbar
(Maven)
May 24, 2022
RCE vulnerability in ElasticBox Jenkins Kubernetes CI/CD Plugin
High
CVE-2020-2211
was published
for
com.elasticbox.jenkins-ci.plugins:kubernetes-ci
(Maven)
May 24, 2022
Stored XSS vulnerability in Coverage/Complexity Scatter Plot Plugin
High
CVE-2020-2265
was published
for
org.jenkins-ci.plugins:covcomplplot
(Maven)
May 24, 2022
Stored XSS vulnerability in Custom Job Icon Plugin
High
CVE-2020-2264
was published
for
org.jenkins-ci.plugins:custom-job-icon
(Maven)
May 24, 2022
System command execution vulnerability in Selection tasks Jenkins Plugin
High
CVE-2020-2276
was published
for
org.jvnet.hudson.plugins:selection-tasks-plugin
(Maven)
May 24, 2022
Complete lack of CSRF protection in Jenkins Selenium Plugin can lead to OS command injection
High
CVE-2020-2196
was published
for
org.jenkins-ci.plugins:selenium
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Valgrind Plugin
High
CVE-2020-2245
was published
for
org.jenkins-ci.plugins:valgrind
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Cadence vManager Plugin
High
CVE-2020-2243
was published
for
org.jenkins-ci.plugins:vmanager-plugin
(Maven)
May 24, 2022
Reflected XSS vulnerability in Jenkins JSGames Plugin
High
CVE-2020-2248
was published
for
org.jenkins-ci.plugins:jsgames
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Valgrind Plugin
High
CVE-2020-2246
was published
for
org.jenkins-ci.plugins:valgrind
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Klocwork Analysis Plugin
High
CVE-2020-2247
was published
for
org.jenkins-ci.plugins:klocwork
(Maven)
May 24, 2022
Remote Code Execution vulnerability in Jenkins Literate Plugin
High
CVE-2020-2158
was published
for
org.jenkins-ci.plugins:literate
(Maven)
May 24, 2022
OS command injection in CryptoMove Plugin
High
CVE-2020-2159
was published
for
io.jenkins.plugins:cryptomove
(Maven)
May 24, 2022
Missing permission check in Coverity Plugin allows capturing credentials
High
CVE-2022-36921
was published
for
org.jenkins-ci.plugins:coverity
(Maven)
Jul 28, 2022
Jenkins Coverity Plugin vulnerable to cross-site request forgery (CSRF)
High
CVE-2022-36920
was published
for
org.jenkins-ci.plugins:coverity
(Maven)
Jul 28, 2022
OS command injection vulnerability in Jenkins Play Framework Plugin
High
CVE-2020-2200
was published
for
org.jenkins-ci.plugins:play-autotest-plugin
(Maven)
May 24, 2022
Missing permission checks in Jenkins Sounds Plugin allow OS command execution
High
CVE-2020-2097
was published
for
org.jenkins-ci.plugins:sounds
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution
High
CVE-2020-2098
was published
for
org.jenkins-ci.plugins:sounds
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API