GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,427
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
335 advisories
Filter by severity
Stored XSS vulnerability in Jenkins Sonargraph Integration Plugin
Moderate
CVE-2020-2201
was published
for
org.jenkins-ci.plugins:sonargraph-integration
(Maven)
May 24, 2022
Users with Overall/Read access could enumerate credentials IDs in Jenkins Fortify on Demand Plugin
Moderate
CVE-2020-2202
was published
for
org.jenkins-ci.plugins:fortify-on-demand-uploader
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Swarm Plugin
Moderate
CVE-2020-2192
was published
for
org.jenkins-ci.plugins:swarm
(Maven)
May 24, 2022
Missing permission check in Jenkins Project Inheritance Plugin
Moderate
CVE-2020-2198
was published
for
hudson.plugins:project-inheritance
(Maven)
May 24, 2022
Missing permission check in Jenkins Project Inheritance Plugin
Moderate
CVE-2020-2197
was published
for
hudson.plugins:project-inheritance
(Maven)
May 24, 2022
XSS vulnerability in Jenkins Subversion Partial Release Manager Plugin
Moderate
CVE-2020-2199
was published
for
org.jenkins-ci.plugins:svn-partial-release-mgr
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Compact Columns Plugin
Moderate
CVE-2020-2195
was published
for
org.jenkins-ci.plugins:compact-columns
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins ECharts API Plugin
Moderate
CVE-2020-2193
was published
for
io.jenkins.plugins:echarts-api
(Maven)
May 24, 2022
Improper permission checks in Jenkins Swarm Plugin
Moderate
CVE-2020-2191
was published
for
org.jenkins-ci.plugins:swarm
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins ECharts API Plugin
Moderate
CVE-2020-2194
was published
for
io.jenkins.plugins:echarts-api
(Maven)
May 24, 2022
Lack of SSL/TLS certificate and hostname validation in Amazon EC2 Plugin
Moderate
CVE-2020-2187
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps
Moderate
CVE-2020-2181
was published
for
org.jenkins-ci.plugins:credentials-binding
(Maven)
May 24, 2022
Missing SSH host key validation in Jenkins Amazon EC2 Plugin
Moderate
CVE-2020-2185
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
Users with Overall/Read access can enumerate credentials IDs in Amazon EC2 Plugin
Moderate
CVE-2020-2188
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins CVS Plugin
Moderate
CVE-2020-2184
was published
for
org.jenkins-ci.plugins:cvs
(Maven)
May 24, 2022
Improper permission checks in Jenkins Copy Artifact Plugin
Moderate
CVE-2020-2183
was published
for
org.jenkins-ci.plugins:copyartifact
(Maven)
May 24, 2022
Credentials stored in plain text by Jenkins Copr Plugin
Moderate
CVE-2020-2177
was published
for
org.fedoraproject.jenkins.plugins:copr
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins FitNesse Plugin
Moderate
CVE-2020-2175
was published
for
org.jenkins-ci.plugins:fitnesse
(Maven)
May 24, 2022
XSS vulnerability in Jenkins Gatling Plugin
Moderate
CVE-2020-2173
was published
for
org.jenkins-ci.plugins:gatling
(Maven)
May 24, 2022
XSS vulnerability in Jenkins useMango Runner Plugin
Moderate
CVE-2020-2176
was published
for
it.infuse.jenkins:usemango-runner
(Maven)
May 24, 2022
Reflected XSS vulnerability in Jenkins AWSEB Deployment Plugin
Moderate
CVE-2020-2174
was published
for
br.com.ingenieux.jenkins.plugins:awseb-deployment-plugin
(Maven)
May 24, 2022
Reflected XSS vulnerability in Jenkins Queue cleanup Plugin
Moderate
CVE-2020-2169
was published
for
org.jenkins-ci.plugins:queue-cleanup
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins RapidDeploy Plugin
Moderate
CVE-2020-2170
was published
for
org.jenkins-ci.plugins:rapiddeploy-jenkins
(Maven)
May 24, 2022
Improper Neutralization of Input During Web Page Generation in Jenkins
Moderate
CVE-2020-2162
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Jenkins Subversion Release Manager Plugin vulnerable to cross-site scripting (XSS)
Moderate
CVE-2020-2152
was published
for
org.jvnet.hudson.plugins:svn-release-mgr
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API