GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
271 advisories
Filter by severity
Improper Input Validation in RESTEasy
High
CVE-2020-1695
was published
for
org.jboss.resteasy:resteasy-client
(Maven)
May 24, 2022
Pebble Templates Improper Input Validation vulnerability
Critical
CVE-2019-19899
was published
for
io.pebbletemplates:pebble-project
(Maven)
May 24, 2022
DNS based denial of service in Apache Wicket
High
CVE-2021-23937
was published
for
org.apache.wicket:wicket-core
(Maven)
May 24, 2022
Lack of type validation in agent related REST API in Jenkins
Moderate
CVE-2021-21639
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Path traversal vulnerability in Jenkins agent names
High
CVE-2021-21605
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Arbitrary file existence check in file fingerprints in Jenkins
Moderate
CVE-2021-21606
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Improper Input Validation in Undertow
High
CVE-2020-1757
was published
for
io.undertow:undertow-core
(Maven)
May 24, 2022
Improper Verification of Cryptographic Signature in Apache Netbeans
High
CVE-2019-17561
was published
for
org.codehaus.mevenide:netbeans
(Maven)
May 24, 2022
RCE vulnerability in Jenkins Azure Container Service Plugin
High
CVE-2020-2168
was published
for
org.jenkins-ci.plugins:azure-acs
(Maven)
May 24, 2022
RCE vulnerability in Jenkins Pipeline: AWS Steps Plugin
High
CVE-2020-2166
was published
for
de.taimos:pipeline-aws
(Maven)
May 24, 2022
RCE vulnerability in Jenkins OpenShift Pipeline Plugin
High
CVE-2020-2167
was published
for
com.openshift.jenkins:openshift-pipeline
(Maven)
May 24, 2022
Improper Input Validation in Jenkins Pipeline: Groovy Plugin
High
CVE-2020-2109
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
May 24, 2022
Improper Input Validation in Jenkins Script Security Plugin
High
CVE-2020-2110
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 24, 2022
Improper Input Validation in Apache Kafka
High
CVE-2018-17196
was published
for
org.apache.kafka:kafka
(Maven)
May 24, 2022
JGit Improper Input Validation vulnerability
Critical
CVE-2014-9390
was published
for
mercurial
(Maven)
May 17, 2022
Drools Improper Input Validation vulnerability allows remote attackers to execute arbitrary code in JBoss EAP
High
CVE-2010-3708
was published
for
org.drools:drools-core
(Maven)
May 17, 2022
Caucho Quercus, as distributed in Resin, does not properly handle unspecified characters in the names of variables
High
CVE-2012-2965
was published
for
com.caucho:resin
(Maven)
May 17, 2022
OpenID4Java does not verify that Attribute Exchange (AX) information is signed
Moderate
CVE-2011-4314
was published
for
org.openid4java:openid4java
(Maven)
May 17, 2022
XML External Entity Reference in RESTEasy
Moderate
CVE-2014-7839
was published
for
org.jboss.resteasy:resteasy-jaxrs
(Maven)
May 17, 2022
Improper Input Validation in Drools and jBPM
High
CVE-2014-8125
was published
for
org.drools:drools-core
(Maven)
May 17, 2022
Jenkins Vulnerable to Denial of Service (DoS)
Low
CVE-2015-1808
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Remote Code Execution in Apache Struts
Critical
CVE-2016-3082
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Denial of service in Apache Struts
Moderate
CVE-2016-3093
was published
for
ognl:ognl
(Maven)
May 17, 2022
Improper Input Validation in Apache ActiveMQ
Moderate
CVE-2015-6524
was published
for
org.apache.activemq:activemq-broker
(Maven)
May 17, 2022
Open redirect in Apache Struts
Moderate
CVE-2013-2248
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API