GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
624 advisories
Filter by severity
Secret stored in plain text by Jenkins Parameterized Remote Trigger Plugin
Low
CVE-2020-2239
was published
for
org.jenkins-ci.plugins:Parameterized-Remote-Trigger
(Maven)
May 24, 2022
Credentials stored in plain text by Jenkins tfs Plugin
Low
CVE-2020-2249
was published
for
org.jenkins-ci.plugins:tfs
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Flaky Test Handler Plugin
Moderate
CVE-2020-2237
was published
for
org.jenkins-ci.plugins:flaky-test-handler
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Pipeline Maven Integration Plugin allow capturing credentials
High
CVE-2020-2235
was published
for
org.jenkins-ci.plugins:pipeline-maven
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Yet Another Build Visualizer Plugin
High
CVE-2020-2236
was published
for
com.axis.system.jenkins.plugins.downstream:yet-another-build-visualizer
(Maven)
May 24, 2022
Jenkins Cross-Site Scripting vulnerability in help icons
High
CVE-2020-2229
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Jenkins Cross-site Scripting vulnerability in project naming strategy
High
CVE-2020-2230
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Jenkins Email Extension Plugin SMTP password transmitted and displayed in plain text
Low
CVE-2020-2232
was published
for
org.jenkins-ci.plugins:email-ext
(Maven)
May 24, 2022
Missing permission check in Jenkins Pipeline Maven Integration Plugin allows enumerating credentials IDs
Moderate
CVE-2020-2233
was published
for
org.jenkins-ci.plugins:pipeline-maven
(Maven)
May 24, 2022
Missing permission check in Jenkins Pipeline Maven Integration Plugin allow capturing credentials
High
CVE-2020-2234
was published
for
org.jenkins-ci.plugins:pipeline-maven
(Maven)
May 24, 2022
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
High
CVE-2020-2228
was published
for
org.jenkins-ci.plugins:gitlab-oauth
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin
High
CVE-2020-2226
was published
for
org.jenkins-ci.plugins:matrix-auth
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins 'keep forever' badge icon
High
CVE-2020-2222
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin
High
CVE-2020-2225
was published
for
org.jenkins-ci.plugins:matrix-project
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Deployer Framework Plugin
High
CVE-2020-2227
was published
for
org.jenkins-ci.plugins:deployer-framework
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins upstream cause
High
CVE-2020-2221
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in single axis builds tooltips in Jenkins Matrix Project Plugin
High
CVE-2020-2224
was published
for
org.jenkins-ci.plugins:matrix-project
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins console links
High
CVE-2020-2223
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins job build time trend
High
CVE-2020-2220
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Link Column Plugin
Moderate
CVE-2020-2219
was published
for
org.jenkins-ci.plugins:link-column
(Maven)
May 24, 2022
Content-Security-Policy protection for user content disabled by Jenkins ZAP Pipeline Plugin
Moderate
CVE-2020-2214
was published
for
com.vrondakis.zap:zap-pipeline
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Zephyr for JIRA Test Management Plugin
Moderate
CVE-2020-2215
was published
for
org.jenkins-ci.plugins:zephyr-for-jira-test-management
(Maven)
May 24, 2022
Reflected XSS in Jenkins Compatibility Action Storage Plugin
Moderate
CVE-2020-2217
was published
for
org.jenkins-ci.plugins:compatibility-action-storage
(Maven)
May 24, 2022
Missing permission checks in Zephyr for JIRA Test Management Plugin
Moderate
CVE-2020-2216
was published
for
org.jenkins-ci.plugins:zephyr-for-jira-test-management
(Maven)
May 24, 2022
Password stored in plain text by Jenkins HP ALM Quality Center Plugin
Low
CVE-2020-2218
was published
for
org.jenkins-ci.plugins:hp-quality-center
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API