GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
210 advisories
Filter by severity
Stored XSS vulnerability in Jenkins job build time trend
High
CVE-2020-2220
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
XSS vulnerability in Jenkins Build Failure Analyzer Plugin
High
CVE-2020-2244
was published
for
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
(Maven)
May 24, 2022
Inbound TCP Agent Protocol/3 authentication bypass in Jenkins
High
CVE-2020-2099
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
XXE vulnerability in NUnit Plugin
High
CVE-2020-2115
was published
for
org.jenkins-ci.plugins:nunit
(Maven)
May 24, 2022
XXE vulnerability in FitNesse Plugin
High
CVE-2020-2120
was published
for
org.jenkins-ci.plugins:fitnesse
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins console links
High
CVE-2020-2223
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in single axis builds tooltips in Jenkins Matrix Project Plugin
High
CVE-2020-2224
was published
for
org.jenkins-ci.plugins:matrix-project
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Deployer Framework Plugin
High
CVE-2020-2227
was published
for
org.jenkins-ci.plugins:deployer-framework
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Git Parameter Plugin
High
CVE-2020-2238
was published
for
org.jenkins-ci.tools:git-parameter
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Database Plugin
High
CVE-2020-2240
was published
for
org.jenkins-ci.plugins:database
(Maven)
May 24, 2022
Improper handling of REST API XML deserialization errors in Jenkins
High
CVE-2021-21604
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
RCE vulnerability in Jenkins Code Coverage API Plugin
High
CVE-2021-21677
was published
for
io.jenkins.plugins:code-coverage-api
(Maven)
May 24, 2022
XML External Entity Reference vulnerability in Jenkins Config File Provider Plugin
High
CVE-2021-21642
was published
for
org.jenkins-ci.plugins:config-file-provider
(Maven)
May 24, 2022
Jenkins SAML Plugin allows bypassing CSRF protection for any URL
High
CVE-2021-21678
was published
for
org.jenkins-ci.plugins:saml
(Maven)
May 24, 2022
Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL
High
CVE-2021-21679
was published
for
org.jenkins-ci.plugins:azure-ad
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Cobertura Plugin
High
CVE-2020-2138
was published
for
org.jenkins-ci.plugins:cobertura
(Maven)
May 24, 2022
RCE vulnerability in RadarGun Plugin
High
CVE-2020-2123
was published
for
org.jenkins-ci.plugins:radargun
(Maven)
May 24, 2022
XXE vulnerability in Rundeck Plugin
High
CVE-2020-2144
was published
for
org.jenkins-ci.plugins:rundeck
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Build With Parameters Plugin
High
CVE-2021-21629
was published
for
org.jenkins-ci.plugins:build-with-parameters
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Yet Another Build Visualizer Plugin
High
CVE-2020-2236
was published
for
com.axis.system.jenkins.plugins.downstream:yet-another-build-visualizer
(Maven)
May 24, 2022
Stored XSS vulnerability in Pipeline Maven Integration Plugin via unescaped display name
High
CVE-2020-2256
was published
for
org.jenkins-ci.plugins:pipeline-maven
(Maven)
May 24, 2022
Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin
High
CVE-2020-2225
was published
for
org.jenkins-ci.plugins:matrix-project
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin
High
CVE-2020-2226
was published
for
org.jenkins-ci.plugins:matrix-auth
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Configuration Slicing Plugin
High
CVE-2021-21617
was published
for
org.jenkins-ci.plugins:configurationslicing
(Maven)
May 24, 2022
Jenkins Cross-site Scripting vulnerability in project naming strategy
High
CVE-2020-2230
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API