GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,688
Erlang
34
GitHub Actions
26
Go
2,274
Maven
5,000+
npm
3,930
NuGet
706
pip
3,696
Pub
12
RubyGems
919
Rust
955
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,494 advisories
Filter by severity
Cross-Site Request Forgery in Jenkins Beaker builder Plugin
Moderate
CVE-2022-34207
was published
for
org.jenkins-ci.plugins:beaker-builder
(Maven)
Jun 24, 2022
Cross-Site Request Forgery in Jenkins ThreadFix Plugin
Moderate
CVE-2022-34209
was published
for
org.jenkins-ci.plugins:threadfix
(Maven)
Jun 24, 2022
Cross-Site Request Forgery in Jenkins Jianliao Notification Plugin
Moderate
CVE-2022-34205
was published
for
org.jenkins-ci.plugins:jianliao
(Maven)
Jun 24, 2022
Missing permission check in Jenkins ThreadFix Plugin
Moderate
CVE-2022-34210
was published
for
org.jenkins-ci.plugins:threadfix
(Maven)
Jun 24, 2022
Cross-Site Request Forgery in Jenkins vRealize Orchestrator Plugin
Moderate
CVE-2022-34211
was published
for
org.jenkins-ci.plugins:vmware-vrealize-orchestrator
(Maven)
Jun 24, 2022
Missing permission check in Jenkins vRealize Orchestrator Plugin
Moderate
CVE-2022-34212
was published
for
org.jenkins-ci.plugins:vmware-vrealize-orchestrator
(Maven)
Jun 24, 2022
Jenkins EasyQA Plugin Missing Authorization vulnerability
Moderate
CVE-2022-34204
was published
for
com.geteasyqa:easyqa
(Maven)
Jun 24, 2022
Jenkins Jianliao Notification Plugin Missing Authorization vulnerability
Moderate
CVE-2022-34206
was published
for
org.jenkins-ci.plugins:jianliao
(Maven)
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
Critical
CVE-2022-33127
was published
for
diffy
(RubyGems)
Jun 24, 2022
Cross-site Scripting in Jfinal CMS
Moderate
CVE-2022-33113
was published
for
com.jfinal:jfinal
(Maven)
Jun 24, 2022
Withdrawn: Denial of Service in aiohttp
Moderate
CVE-2022-33124
was published
for
aiohttp
(pip)
Jun 24, 2022
•
withdrawn
Observable timing discrepancy allows determining username validity in Jenkins
Moderate
CVE-2022-34174
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 24, 2022
Cross-site Scripting vulnerability in Jenkins
High
CVE-2022-34170
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 24, 2022
Improper authorization in Jenkins Embeddable Build Status Plugin bypasses ViewStatus permission requirement
Moderate
CVE-2022-34180
was published
for
org.jenkins-ci.plugins:embeddable-build-status
(Maven)
Jun 24, 2022
Cross-site Scripting in Jenkins Agent Server Parameter Plugin
High
CVE-2022-34183
was published
for
io.jenkins.plugins:agent-server-parameter
(Maven)
Jun 24, 2022
Cross-site Scripting in Jenkins Package Version Plugin
High
CVE-2022-34193
was published
for
org.lilicurroad.jenkins:packageversion
(Maven)
Jun 24, 2022
Cross-site Scripting in Jenkins Date Parameter Plugin
High
CVE-2022-34185
was published
for
me.leejay.jenkins:date-parameter
(Maven)
Jun 24, 2022
Cross-Site Request Forgery in Jenkins Convertigo Mobile Platform Plugin
Moderate
CVE-2022-34200
was published
for
com.convertigo.jenkins.plugins:convertigo-mobile-platform
(Maven)
Jun 24, 2022
Cross-Site Request Forgery in Jenkins EasyQA Plugin
Moderate
CVE-2022-34203
was published
for
com.geteasyqa:easyqa
(Maven)
Jun 24, 2022
Cross-site Scripting in Jenkins NS-ND Integration Performance Publisher Plugin
High
CVE-2022-34191
was published
for
io.jenkins.plugins:cavisson-ns-nd-integration
(Maven)
Jun 24, 2022
User passwords stored in plain text by Jenkins EasyQA Plugin
Low
CVE-2022-34202
was published
for
com.geteasyqa:easyqa
(Maven)
Jun 24, 2022
Cross-site Scripting in Jenkins Dynamic Extended Choice Parameter Plugin
High
CVE-2022-34186
was published
for
com.moded.extendedchoiceparameter:dynamic_extended_choice_parameter
(Maven)
Jun 24, 2022
Cross-site Scripting in Jenkins ontrack Jenkins Plugin
High
CVE-2022-34192
was published
for
org.jenkins-ci.plugins:ontrack
(Maven)
Jun 24, 2022
Cross-site Scripting in Jenkins Hidden Parameter Plugin
High
CVE-2022-34188
was published
for
org.jenkins-ci.plugins:hidden-parameter
(Maven)
Jun 24, 2022
Cross-site Scripting in Jenkins Maven Metadata Plugin
High
CVE-2022-34190
was published
for
eu.markov.jenkins.plugin.mvnmeta:maven-metadata-plugin
(Maven)
Jun 24, 2022
ProTip!
Advisories are also available from the
GraphQL API