GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
6,776 advisories
Filter by severity
This vulnerability allows remote attackers to disclose sensitive information on vulnerable...
Moderate
Unreviewed
CVE-2018-9948
was published
May 13, 2022
This vulnerability allows remote attackers to disclose sensitive information on vulnerable...
Moderate
Unreviewed
CVE-2018-9946
was published
May 13, 2022
GitHub Authentication Plugin showed plain text client secret in configuration form
Moderate
CVE-2019-1003018
was published
for
org.jenkins-ci.plugins:github-oauth
(Maven)
May 13, 2022
Jenkins OpenId Connect Authentication Plugin showed plain text client secret in configuration form
Moderate
CVE-2019-1003021
was published
for
org.jenkins-ci.plugins:oic-auth
(Maven)
May 13, 2022
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its...
Moderate
Unreviewed
CVE-2019-10243
was published
May 13, 2022
A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an...
Moderate
Unreviewed
CVE-2019-1645
was published
May 13, 2022
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an...
Moderate
Unreviewed
CVE-2019-1762
was published
May 13, 2022
Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0...
Moderate
Unreviewed
CVE-2019-3610
was published
May 13, 2022
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because...
Moderate
Unreviewed
CVE-2017-14955
was published
May 13, 2022
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for...
Moderate
Unreviewed
CVE-2014-8775
was published
May 13, 2022
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0...
Moderate
Unreviewed
CVE-2011-1015
was published
May 13, 2022
Phusion Passenger information disclosure
Moderate
CVE-2017-16355
was published
for
passenger
(RubyGems)
May 13, 2022
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related...
Moderate
Unreviewed
CVE-2018-19854
was published
May 13, 2022
The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows...
Moderate
Unreviewed
CVE-2014-0153
was published
May 13, 2022
Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php...
Moderate
Unreviewed
CVE-2011-3791
was published
May 13, 2022
Exposure of sensitive information in Anchore Container Image Scanner Jenkins Plugin
Moderate
CVE-2018-1999033
was published
for
org.jenkins-ci.plugins:anchore-container-scanner
(Maven)
May 13, 2022
sosreport sensitive information disclosure via weak permissions of the generated archives
Moderate
CVE-2015-3171
was published
for
sosreport
(pip)
May 13, 2022
A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All...
Moderate
Unreviewed
CVE-2016-8672
was published
May 13, 2022
Jenkins allows Unauthorized Viewing of Queue API Information
Moderate
CVE-2015-5324
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2015-5320
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Jenkins has Information Disclosure via Sidepanel Widget
Moderate
CVE-2015-5321
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
jose-php before 2.2.1 does not use constant-time operations for HMAC comparison, which makes it...
Moderate
Unreviewed
CVE-2016-5429
was published
May 13, 2022
The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1...
Moderate
Unreviewed
CVE-2016-5430
was published
May 13, 2022
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information...
Moderate
Unreviewed
CVE-2014-8566
was published
May 13, 2022
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers...
Moderate
Unreviewed
CVE-2016-5265
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API