GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,041
Maven
5,000+
npm
3,733
NuGet
662
pip
3,414
Pub
12
RubyGems
891
Rust
866
Swift
36
Unreviewed advisories
All unreviewed
5,000+
20,892 advisories
Filter by severity
Singularity insecure permissions
High
CVE-2019-19724
was published
for
github.com/sylabs/singularity
(Go)
May 24, 2022
Treekill Enables OS Command Injection
Critical
CVE-2019-15598
was published
for
tree-kill
(npm)
May 24, 2022
Duplicate Advisory: tree-kill vulnerable to remote code execution
Critical
GHSA-mxq6-vrrr-ppmg
was published
for
tree-kill
(npm)
May 24, 2022
•
withdrawn
TYPO3 SQL Injection in low-level Query Generator
Moderate
CVE-2019-19850
was published
for
typo3/cms
(Composer)
May 24, 2022
TYPO3 Insecure Deserialization in Query Generator & Query View
High
CVE-2019-19849
was published
for
typo3/cms
(Composer)
May 24, 2022
TYPO3 Directory Traversal on ZIP extraction
Moderate
CVE-2019-19848
was published
for
typo3/cms
(Composer)
May 24, 2022
Jenkins Alauda DevOps Pipeline Plugin allows attackers with Overall/Read permission to capture credentials stored in Jenkins
Moderate
CVE-2019-16574
was published
for
com.alauda.jenkins.plugins:alauda-devops-pipeline
(Maven)
May 24, 2022
Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin
High
CVE-2019-16575
was published
for
io.alauda.jenkins.plugins:alauda-kubernetes-support
(Maven)
May 24, 2022
Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin
Moderate
CVE-2019-16576
was published
for
io.alauda.jenkins.plugins:alauda-kubernetes-support
(Maven)
May 24, 2022
Jenkins Weibo Plugin stores credentials unencrypted in its global configuration file
Low
CVE-2019-16572
was published
for
org.jenkins-ci.plugins:weibo
(Maven)
May 24, 2022
Cross site scripting in Jenkins Mission Control Plugin
Moderate
CVE-2019-16563
was published
for
tech.andrey.jenkins:mission-control-view
(Maven)
May 24, 2022
Jenkins Alauda DevOps Pipeline Plugin vulnerable to cross-site request forgery
High
CVE-2019-16573
was published
for
com.alauda.jenkins.plugins:alauda-devops-pipeline
(Maven)
May 24, 2022
Jenkins SCTMExecutor Plugin stores credentials in plain text
Moderate
CVE-2019-16568
was published
for
hudson.plugins.sctmexecutor:SCTMExecutor
(Maven)
May 24, 2022
Jenkins RapidDeploy Plugin missing permission check
Moderate
CVE-2019-16571
was published
for
org.jenkins-ci.plugins:rapiddeploy-jenkins
(Maven)
May 24, 2022
Jenkins RapidDeploy Plugin Cross-Site Request Forgery plugin
Moderate
CVE-2019-16570
was published
for
org.jenkins-ci.plugins:rapiddeploy-jenkins
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Mantis Plugin
Moderate
CVE-2019-16569
was published
for
org.jenkins-ci.plugins:mantis
(Maven)
May 24, 2022
Jenkins Team Concert Plugin missing permission check
Moderate
CVE-2019-16567
was published
for
org.jenkins-ci.plugins:teamconcert
(Maven)
May 24, 2022
Jenkins Team Concert Plugin missing permission check
High
CVE-2019-16566
was published
for
org.jenkins-ci.plugins:teamconcert
(Maven)
May 24, 2022
Jenkins Pipeline Aggregator View Plugin stored XSS vulnerability
Moderate
CVE-2019-16564
was published
for
com.paul8620.jenkins.plugins:pipeline-aggregator-view
(Maven)
May 24, 2022
Jenkins Team Concert Plugin cross-site request forgery vulnerability
High
CVE-2019-16565
was published
for
org.jenkins-ci.plugins:teamconcert
(Maven)
May 24, 2022
Jenkins WebSphere Deployer Plugin missing permission check
Moderate
CVE-2019-16559
was published
for
org.jenkins-ci.plugins:websphere-deployer
(Maven)
May 24, 2022
SSL/TLS certificate validation globally and unconditionally disabled by Jenkins WebSphere Deployer Plugin
High
CVE-2019-16561
was published
for
org.jenkins-ci.plugins:websphere-deployer
(Maven)
May 24, 2022
Missing permission check in Jenkins Build Failure Analyzer Plugin
Moderate
CVE-2019-16554
was published
for
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
(Maven)
May 24, 2022
Jenkins Rundeck Plugin stored credentials in plain text
Moderate
CVE-2019-16556
was published
for
org.jenkins-ci.plugins:rundeck
(Maven)
May 24, 2022
Jenkins Redgate SQL Change Automation Plugin has Insufficiently Protected Credentials
Moderate
CVE-2019-16557
was published
for
com.redgate.plugins.redgatesqlci:redgate-sql-ci
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API