GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,951
Erlang
39
GitHub Actions
38
Go
2,607
Maven
5,000+
npm
4,251
NuGet
757
pip
4,017
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,705 advisories
Filter by severity
An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a...
Moderate
Unreviewed
CVE-2020-29561
was published
May 24, 2022
Missing permission checks in Jenkins Chaos Monkey Plugin
Moderate
CVE-2020-2323
was published
for
io.jenkins.plugins:chaos-monkey
(Maven)
May 24, 2022
Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0,...
Moderate
Unreviewed
CVE-2020-29138
was published
May 24, 2022
Missing Authorization in Crafter CMS
Moderate
CVE-2017-15680
was published
for
org.craftercms:crafter-core
(Maven)
May 24, 2022
SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he...
Moderate
Unreviewed
CVE-2020-6316
was published
May 24, 2022
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES...
Moderate
Unreviewed
CVE-2020-28368
was published
May 24, 2022
In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due...
Moderate
Unreviewed
CVE-2020-0454
was published
May 24, 2022
An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0...
Moderate
Unreviewed
CVE-2020-26506
was published
May 24, 2022
Missing authorization in Jenkins Kubernetes Plugin
Moderate
CVE-2020-2309
was published
for
org.csanchez.jenkins.plugins:kubernetes
(Maven)
May 24, 2022
Missing permission checks in Jenkins Azure Key Vault Plugin allow enumerating credentials IDs
Moderate
CVE-2020-2313
was published
for
org.jenkins-ci.plugins:azure-keyvault
(Maven)
May 24, 2022
Missing permission checks in Jenkins Ansible Plugin allow enumerating credentials IDs
Moderate
CVE-2020-2310
was published
for
org.jenkins-ci.plugins:ansible
(Maven)
May 24, 2022
Missing permission check in Jenkins AWS Global Configuration Plugin allows replacing plugin configuration
Moderate
CVE-2020-2311
was published
for
io.jenkins.plugins:aws-global-configuration
(Maven)
May 24, 2022
Missing Authorization in Jenkins Kubernetes Plugin
Moderate
CVE-2020-2308
was published
for
org.csanchez.jenkins.plugins:kubernetes
(Maven)
May 24, 2022
Missing Authorization in Jenkins Mercurial Plugin
Moderate
CVE-2020-2306
was published
for
org.jenkins-ci.plugins:mercurial
(Maven)
May 24, 2022
Missing permission check in Jenkins Active Directory Plugin allows accessing domain health check page
Moderate
CVE-2020-2302
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 24, 2022
This issue was addressed with improved checks to prevent unauthorized actions. This issue is...
Moderate
Unreviewed
CVE-2020-9982
was published
May 24, 2022
An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was...
Moderate
Unreviewed
CVE-2019-8856
was published
May 24, 2022
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2019-8855
was published
May 24, 2022
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
Moderate
Unreviewed
CVE-2020-26650
was published
May 24, 2022
A flaw was found in Infinispan version 10, where it permits local access to controls via both...
Moderate
Unreviewed
CVE-2020-10746
was published
May 24, 2022
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys...
Moderate
Unreviewed
CVE-2020-14185
was published
May 24, 2022
Missing permission checks in Jenkins Maven Cascade Release Plugin
Moderate
CVE-2020-2294
was published
for
com.barchart.jenkins:maven-release-cascade
(Maven)
May 24, 2022
A vulnerability in the Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco 4000 Series...
Moderate
Unreviewed
CVE-2020-3524
was published
May 24, 2022
Missing permission check in Jenkins Implied Labels Plugin allows reconfiguring the plugin
Moderate
CVE-2020-2282
was published
for
org.jenkins-ci.plugins:implied-labels
(Maven)
May 24, 2022
Missing permission check in Jenkins Liquibase Runner Plugin allows enumerating credentials IDs
Moderate
CVE-2020-2285
was published
for
org.jenkins-ci.plugins:liquibase-runner
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API