GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,355
NuGet
765
pip
4,115
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,643 advisories
Filter by severity
Missing permission checks in Health Advisor by CloudBees Plugin
Moderate
CVE-2020-2094
was published
for
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
(Maven)
May 24, 2022
Missing permission checks in Jenkins Amazon EC2 Plugin
Moderate
CVE-2020-2091
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed...
Moderate
Unreviewed
CVE-2019-19985
was published
May 24, 2022
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0...
Moderate
Unreviewed
CVE-2019-15013
was published
May 24, 2022
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12...
Moderate
Unreviewed
CVE-2019-15576
was published
May 24, 2022
Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin
Moderate
CVE-2019-16576
was published
for
io.alauda.jenkins.plugins:alauda-kubernetes-support
(Maven)
May 24, 2022
Jenkins Alauda DevOps Pipeline Plugin allows attackers with Overall/Read permission to capture credentials stored in Jenkins
Moderate
CVE-2019-16574
was published
for
com.alauda.jenkins.plugins:alauda-devops-pipeline
(Maven)
May 24, 2022
Jenkins RapidDeploy Plugin missing permission check
Moderate
CVE-2019-16571
was published
for
org.jenkins-ci.plugins:rapiddeploy-jenkins
(Maven)
May 24, 2022
Jenkins Team Concert Plugin missing permission check
High
CVE-2019-16566
was published
for
org.jenkins-ci.plugins:teamconcert
(Maven)
May 24, 2022
Jenkins Team Concert Plugin missing permission check
Moderate
CVE-2019-16567
was published
for
org.jenkins-ci.plugins:teamconcert
(Maven)
May 24, 2022
Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed...
Moderate
Unreviewed
CVE-2019-13748
was published
May 24, 2022
SiteVision 4 has Incorrect Access Control.
High
Unreviewed
CVE-2019-12734
was published
May 24, 2022
A flaw was discovered in ibus that allows any unprivileged user to monitor and send method calls...
Low
Unreviewed
CVE-2019-14822
was published
May 24, 2022
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x, 16.x, and 17.x, and...
Moderate
Unreviewed
CVE-2019-18790
was published
May 24, 2022
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified...
High
Unreviewed
CVE-2019-18610
was published
May 24, 2022
Jenkins Google Compute Engine Plugin Missing Authorization vulnerability
Moderate
CVE-2019-16547
was published
for
org.jenkins-ci.plugins:google-compute-engine
(Maven)
May 24, 2022
An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an...
Moderate
Unreviewed
CVE-2019-6121
was published
May 24, 2022
An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping...
Moderate
Unreviewed
CVE-2019-18674
was published
May 24, 2022
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8...
Moderate
Unreviewed
CVE-2019-16909
was published
May 24, 2022
An issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin,...
Moderate
Unreviewed
CVE-2019-5095
was published
May 24, 2022
An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files...
High
Unreviewed
CVE-2019-18383
was published
May 24, 2022
Missing permission check in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin
Moderate
CVE-2019-10457
was published
for
org.jenkins-ci.plugins:oracle-cloud-infrastructure-compute-classic
(Maven)
May 24, 2022
Missing permission check in Jenkins Rundeck Plugin
Moderate
CVE-2019-10455
was published
for
org.jenkins-ci.plugins:rundeck
(Maven)
May 24, 2022
Missing permission checks in Google Kubernetes Engine Jenkins Plugin
Moderate
CVE-2019-10445
was published
for
org.jenkins-ci.plugins:google-kubernetes-engine
(Maven)
May 24, 2022
Jenkins iceScrum Plugin vulnerable to Missing Authorization
Moderate
CVE-2019-10442
was published
for
org.jenkins-ci.plugins:icescrum
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API