GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,343
Erlang
31
GitHub Actions
22
Go
2,107
Maven
5,000+
npm
3,764
NuGet
679
pip
3,452
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
335 advisories
Filter by severity
Missing permission check in Jenkins Delete log Plugin
Moderate
CVE-2022-45394
was published
for
org.jenkins-ci.plugins:delete-log-plugin
(Maven)
Nov 16, 2022
Plaintext Storage of a Password in Jenkins NS-ND Integration Performance Publisher Plugin
Moderate
CVE-2022-45392
was published
for
io.jenkins.plugins:cavisson-ns-nd-integration
(Maven)
Nov 16, 2022
Cross-Site Request Forgery in Jenkins Delete log Plugin
Moderate
CVE-2022-45393
was published
for
org.jenkins-ci.plugins:delete-log-plugin
(Maven)
Nov 16, 2022
Jenkins NS-ND Integration Performance Publisher Plugin disables SSL/TLS certificate validation globally and unconditionally
Moderate
CVE-2022-45391
was published
for
io.jenkins.plugins:cavisson-ns-nd-integration
(Maven)
Nov 16, 2022
XML External Entity Reference in Jenkins Violations Plugin
Moderate
CVE-2022-45386
was published
for
org.jenkins-ci.plugins:violations
(Maven)
Nov 16, 2022
SSL/TLS certificate validation unconditionally disabled by Jenkins NS-ND Integration Performance Publisher Plugin
Moderate
CVE-2022-38666
was published
for
org.jenkins-ci.main:cavisson-ns-nd-integration
(Maven)
Nov 16, 2022
Jenkins Reverse Proxy Auth Plugin vulnerable due to plaintext storage of passwords
Moderate
CVE-2022-45384
was published
for
org.jenkins-ci.main:reverse-proxy-auth-plugin
(Maven)
Nov 16, 2022
Stored Cross-site Scripting vulnerabilities in Jenkins Extended Choice Parameter Plugin
Moderate
CVE-2022-29038
was published
for
org.jenkins-ci.plugins:extended-choice-parameter
(Maven)
Apr 13, 2022
Stored XSS vulnerability in Jenkins Bitbucket Server Integration Plugin
Moderate
CVE-2022-28133
was published
for
io.jenkins.plugins:atlassian-bitbucket-server-integration
(Maven)
Mar 30, 2022
Stored Cross-site Scripting vulnerability in Jenkins Tests Selector Plugin
Moderate
CVE-2022-28159
was published
for
org.jenkins-ci.plugins:selected-tests-executor
(Maven)
Mar 30, 2022
Stored Cross-site Scripting vulnerability in Jenkins Job Generator Plugin
Moderate
CVE-2022-29042
was published
for
org.jenkins-ci.plugins:jobgenerator
(Maven)
Apr 13, 2022
Stored Cross-site Scripting in Jenkins Node and Label parameter Plugin
Moderate
CVE-2022-29044
was published
for
org.jenkins-ci.plugins:nodelabelparameter
(Maven)
Apr 13, 2022
Stored Cross-site Scripting vulnerability in Jenkins Subversion Plugin
Moderate
CVE-2022-29046
was published
for
org.jenkins-ci.plugins:subversion
(Maven)
Apr 13, 2022
Stored Cross-site Scripting vulnerability in Jenkins Jira Plugin
Moderate
CVE-2022-29041
was published
for
org.jenkins-ci.plugins:jira
(Maven)
Apr 13, 2022
Stored Cross-site Scripting in Jenkins Mask Passwords Plugin
Moderate
CVE-2022-29043
was published
for
org.jenkins-ci.plugins:mask-passwords
(Maven)
Apr 13, 2022
CSRF vulnerability in Jenkins Subversion Plugin
Moderate
CVE-2022-29048
was published
for
org.jenkins-ci.plugins:subversion
(Maven)
Apr 13, 2022
Arbitrary file read vulnerability in Jenkins Tests Selector Plugin
Moderate
CVE-2022-28160
was published
for
org.jenkins-ci.plugins:selected-tests-executor
(Maven)
Mar 30, 2022
Plaintext storage in Jenkins instant-messaging Plugin
Moderate
CVE-2022-28135
was published
for
org.jvnet.hudson.plugins:instant-messaging
(Maven)
Mar 30, 2022
Passwords stored in plain text by Jenkins dbCharts Plugin
Moderate
CVE-2022-27216
was published
for
org.jenkins-ci.plugins:dbCharts
(Maven)
Mar 16, 2022
Missing permission check in Jenkins RocketChat Notifier Plugin
Moderate
CVE-2022-28139
was published
for
org.jenkins-ci.plugins:rocketchatnotifier
(Maven)
Mar 30, 2022
CSRF vulnerability in Jenkins RocketChat Notifier Plugin
Moderate
CVE-2022-28138
was published
for
org.jenkins-ci.plugins:rocketchatnotifier
(Maven)
Mar 30, 2022
Stored Cross-site Scripting vulnerability in Jenkins Dashboard View Plugin
Moderate
CVE-2022-27197
was published
for
org.jenkins-ci.plugins:dashboard-view
(Maven)
Mar 16, 2022
Stored Cross-site Scripting vulnerability in Jenkins List Git Branches Parameter Plugin
Moderate
CVE-2022-27212
was published
for
org.jenkins-ci.plugins:list-git-branches-parameter
(Maven)
Mar 16, 2022
Stored Cross-site Scripting vulnerability in Jenkins Team Views Plugin
Moderate
CVE-2022-25203
was published
for
com.sonymobile.jenkins.plugins.teamviews:team-views
(Maven)
Feb 16, 2022
Protection Mechanism Failure in Jenkins Doktor Plugin
Moderate
CVE-2022-25204
was published
for
by.dev.madhead.doktor:doktor
(Maven)
Feb 16, 2022
ProTip!
Advisories are also available from the
GraphQL API