GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
326 advisories
Filter by severity
Lack of authentication mechanism in Jenkins DotCi Plugin webhook
Moderate
CVE-2022-41238
was published
for
com.groupon.jenkins-ci.plugins:DotCi
(Maven)
Sep 22, 2022
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
High
CVE-2025-22235
was published
for
org.springframework.boot:spring-boot
(Maven)
Apr 28, 2025
Jenkins Cadence vManager Plugin is Missing Permission Checks
Moderate
CVE-2025-47887
was published
for
org.jenkins-ci.plugins:vmanager-plugin
(Maven)
May 14, 2025
The WikiManager REST API allows any user to create wikis
High
CVE-2025-29926
was published
for
org.xwiki.platform:xwiki-platform-wiki-rest-default
(Maven)
Mar 19, 2025
XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API
Moderate
CVE-2025-46554
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Apr 30, 2025
Any user with view access to the XWiki space can change the authenticator
High
CVE-2025-46557
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-ui
(Maven)
Apr 30, 2025
Missing permission check in Jenkins loader.io Plugin allows enumerating credentials IDs
Moderate
CVE-2022-45390
was published
for
io.loader:loaderio-jenkins-plugin
(Maven)
Nov 16, 2022
org.xwiki.platform:xwiki-platform-component-wiki provides no warning when granting XWiki.ComponentClass programming right
Critical
CVE-2025-32973
was published
for
org.xwiki.platform:xwiki-platform-component-wiki
(Maven)
Apr 29, 2025
Apache Archiva does not require entry of the administrator's password at the time of modifying a user account
Moderate
CVE-2010-4408
was published
for
org.apache.archiva:archiva
(Maven)
May 14, 2022
Jenkins Missing Permission Check
Moderate
CVE-2025-31721
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Apr 2, 2025
Jenkins Missing Permission Check
Moderate
CVE-2025-31720
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Apr 2, 2025
Spring Security Missing Authorization vulnerability
Moderate
CVE-2024-38810
was published
for
org.springframework.security:spring-security-core
(Maven)
Aug 20, 2024
Missing permission checks in Jenkins Chaos Monkey Plugin
High
CVE-2020-2322
was published
for
io.jenkins.plugins:chaos-monkey
(Maven)
May 24, 2022
Apache NiFi: Missing Complete Authorization for Parameter and Service References
Low
CVE-2024-56512
was published
for
org.apache.nifi:nifi-web-api
(Maven)
Dec 28, 2024
Missing permission checks in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24403
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
Missing Authorization to enable or disable users in org.xwiki.platform:xwiki-platform-user-profile-ui
Critical
CVE-2022-41930
was published
for
org.xwiki.platform:xwiki-platform-user-profile-ui
(Maven)
Nov 21, 2022
Jenkins AppSpider Plugin missing permission checks
Moderate
CVE-2024-28155
was published
for
com.rapid7:jenkinsci-appspider-plugin
(Maven)
Mar 6, 2024
Command injection in nevado-jms
High
CVE-2023-31826
was published
for
org.skyscreamer:nevado-jms
(Maven)
May 23, 2023
Missing Authorization in Jenkins Blue Ocean Plugin
Moderate
CVE-2017-1000105
was published
for
io.jenkins.blueocean:blueocean
(Maven)
May 13, 2022
XWiki Realtime WYSIWYG Editor extension allows privilege escalation (PR) through realtime WYSIWYG editing
Critical
CVE-2025-23025
was published
for
org.xwiki.platform:xwiki-platform-realtime-wysiwyg-ui
(Maven)
Jan 14, 2025
XWiki allows RCE from script right in configurable sections
Critical
CVE-2024-55879
was published
for
org.xwiki.platform:xwiki-platform-administration-ui
(Maven)
Dec 12, 2024
XWiki's scheduler in subwiki allows scheduling operations for any main wiki user
Moderate
CVE-2024-55876
was published
for
org.xwiki.platform:xwiki-platform-scheduler-ui
(Maven)
Dec 12, 2024
Apache IoTDB grafana-connector contains an interface without authorization
High
CVE-2022-38370
was published
for
org.apache.iotdb:iotdb-grafana-connector
(Maven)
Sep 6, 2022
Script security bypass vulnerability in Jenkins Shared Library Version Override Plugin
High
CVE-2024-52554
was published
for
io.jenkins.plugins:shared-library-version-override
(Maven)
Nov 13, 2024
Missing permission check in Jenkins Script Security Plugin
Moderate
CVE-2024-52549
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Nov 13, 2024
ProTip!
Advisories are also available from the
GraphQL API