Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,143 advisories

Loading
XXE vulnerability in Jenkins RapidDeploy Plugin High
CVE-2020-2171 was published for org.jenkins-ci.plugins:rapiddeploy-jenkins (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
RCE vulnerability in Jenkins Azure Container Service Plugin High
CVE-2020-2168 was published for org.jenkins-ci.plugins:azure-acs (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
Stored XSS vulnerability in Jenkins RapidDeploy Plugin Moderate
CVE-2020-2170 was published for org.jenkins-ci.plugins:rapiddeploy-jenkins (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
RCE vulnerability in Jenkins Pipeline: AWS Steps Plugin High
CVE-2020-2166 was published for de.taimos:pipeline-aws (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
Passwords stored in plain text by Mail Commander Plugin for Jenkins-ci Plugin Moderate
CVE-2020-2318 was published for org.jenkins-ci.plugins:mailcommander (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
Apache Derby exposes user and password attributes Moderate
CVE-2005-4849 was published for org.apache.derby:derby (Maven) May 1, 2022
Serialization vulnerability in Apache Tapestry Critical
CVE-2020-17531 was published for org.apache.tapestry:tapestry-project (Maven) Feb 9, 2022
JXPath Out-of-bounds Write vulnerability Moderate
CVE-2022-40158 was published for commons-jxpath:commons-jxpath (Maven) Oct 6, 2022 withdrawn
JXPath Out-of-bounds Write vulnerability Moderate
CVE-2022-40161 was published for commons-jxpath:commons-jxpath (Maven) Oct 6, 2022 withdrawn
JXPath Out-of-bounds Write vulnerability Moderate
CVE-2022-40159 was published for commons-jxpath:commons-jxpath (Maven) Oct 6, 2022 withdrawn
JXPath Out-of-bounds Write vulnerability Moderate
CVE-2022-40157 was published for commons-jxpath:commons-jxpath (Maven) Oct 6, 2022 withdrawn
Duplicate Advisory: Keycloak vulnerable to Cross-Site Scripting (XSS) Moderate
GHSA-w8v7-c7pm-7wfr was published for org.keycloak:keycloak-core (Maven) Sep 2, 2022 withdrawn
Venice vulnerable to Partial Path Traversal issue within the functions `load-file` and `load-resource` Moderate
CVE-2022-36007 was published for com.github.jlangch:venice (Maven) Aug 18, 2022
JLLeitschuh
Credited to JLLeitschuh
Google Play Services SDK leads to apps having incorrectly set mutability flag Moderate
CVE-2022-2390 was published for com.google.android.gms:play-services-basement (Maven) Aug 13, 2022
4thline cling uPnP protocol issue can lead to denial of service High
CVE-2020-23622 was published for org.fourthline.cling:cling-core (Maven) Aug 16, 2022
Path Traversal In MeterSpere leads to upload file to any path High
CVE-2022-46178 was published for io.metersphere:metersphere (Maven) Dec 30, 2022
Undertow vulnerable to Dos via Large AJP request High
CVE-2022-2053 was published for io.undertow:undertow-core (Maven) Aug 6, 2022
Business Logic Errors in Para Moderate
CVE-2022-1848 was published for com.erudika:para-core (Maven) May 25, 2022
Multiple components in Apache NiFi do not restrict XML External Entity references High
CVE-2022-29265 was published for org.apache.nifi:nifi (Maven) May 1, 2022
Deserialization of Untrusted Data in logback Moderate
CVE-2021-42550 was published for ch.qos.logback:logback-core (Maven) Dec 17, 2021
MikeMoore63
Credited to MikeMoore63
Stored XSS vulnerability in Jenkins brakeman Plugin Moderate
CVE-2020-2122 was published for org.jenkins-ci.plugins:brakeman (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
Vuetify Cross-site Scripting vulnerability Moderate
CVE-2022-25873 was published for org.webjars.npm:vuetify (Maven) Sep 19, 2022
RCE vulnerability in Google Kubernetes Engine Plugin High
CVE-2020-2121 was published for org.jenkins-ci.plugins:google-kubernetes-engine (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
Credentials transmitted in plain text by OpenShift Deployer Plugin Low
CVE-2020-2155 was published for org.jenkins-ci.plugins:openshift-deployer (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
Credentials transmitted in plain text by Repository Connector Plugin Low
CVE-2020-2149 was published for org.jenkins-ci.plugins:repository-connector (Maven) May 24, 2022
NotMyFault
Credited to NotMyFault
ProTip! Advisories are also available from the GraphQL API