GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
9,971 advisories
Filter by severity
Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin
Moderate
CVE-2017-1000505
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2018-1000192
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Moderate
CVE-2015-1776
was published
for
org.apache.hadoop:hadoop-common
(Maven)
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2017-2609
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
High
CVE-2018-3831
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java
Moderate
CVE-2017-3586
was published
for
mysql:mysql-connector-java
(Maven)
May 13, 2022
Improper Certificate Handling
Moderate
CVE-2020-9321
was published
for
github.com/traefik/traefik
(Go)
Sep 2, 2021
Exposure of Sensitive Information to an Unauthorized Actor in Undertow
Moderate
CVE-2018-14642
was published
for
io.undertow:undertow-core
(Maven)
May 13, 2022
Phusion Passenger information disclosure
Moderate
CVE-2017-16355
was published
for
passenger
(RubyGems)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
Low
CVE-2017-2651
was published
for
org.jenkins-ci.plugins:mailer
(Maven)
May 13, 2022
Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to...
Moderate
Unreviewed
CVE-2018-20237
was published
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2017-1000398
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
Moderate
CVE-2016-6345
was published
for
org.jboss.resteasy:resteasy-client
(Maven)
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Critical
CVE-2016-3086
was published
for
org.apache.hadoop:hadoop-yarn-server-nodemanager
(Maven)
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2017-1000395
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in JGroup
Moderate
CVE-2013-4112
was published
for
org.jgroups:jgroups
(Maven)
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2018-1000068
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module...
Moderate
Unreviewed
CVE-2019-5017
was published
May 24, 2022
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be...
Moderate
Unreviewed
CVE-2022-28774
was published
May 12, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Jasypt
High
CVE-2014-9970
was published
for
org.jasypt:jasypt
(Maven)
May 14, 2022
An information disclosure vulnerability exists in the Multi-Camera interface used by the Foscam...
High
Unreviewed
CVE-2017-2874
was published
May 13, 2022
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows...
Moderate
Unreviewed
CVE-2022-36834
was published
Aug 6, 2022
GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing...
Moderate
Unreviewed
CVE-2020-10087
was published
May 24, 2022
An exploitable local information leak vulnerability exists in the privileged helper tool of GOG...
Moderate
Unreviewed
CVE-2018-4052
was published
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in OpenSAML
Moderate
CVE-2013-6440
was published
for
org.opensaml:opensaml
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API