GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,293
Erlang
31
GitHub Actions
21
Go
2,061
Maven
5,000+
npm
3,744
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
349 advisories
Filter by severity
Improper Control of Generation of Code in Apache Struts
High
CVE-2013-1965
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
Moderate severity vulnerability that affects org.springframework:spring-core
Moderate
CVE-2015-0201
was published
for
org.springframework:spring-core
(Maven)
Oct 17, 2018
Spring Security and Spring Framework may not recognize certain paths that should be protected
High
CVE-2016-5007
was published
for
org.springframework.security:spring-security-core
(Maven)
Oct 17, 2018
Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
High
CVE-2016-9878
was published
for
org.springframework:spring-webmvc
(Maven)
Oct 4, 2018
Spring Framework Cross Site Tracing (XST)
Moderate
CVE-2018-11039
was published
for
org.springframework:spring-web
(Maven)
Oct 16, 2018
Jenkins directory traversal vulnerability
Moderate
CVE-2014-2059
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkin allows attackers to obtain passwords by reading the HTML source code
Moderate
CVE-2014-2061
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins does not invalidate the API token when a user is deleted
Moderate
CVE-2014-2062
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins allows attackers to determine whether a user exists
Moderate
CVE-2014-2064
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins cross-site scripting (XSS) vulnerability
Moderate
CVE-2014-2065
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins session fixation vulnerability
Moderate
CVE-2014-2066
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins cross-site scripting (XSS) vulnerability
Moderate
CVE-2014-2067
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins allows attackers to obtain sensitive information
Low
CVE-2014-2068
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins allows attackers to execute arbitrary jobs
Moderate
CVE-2014-2058
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins CLI Deserialization of Untrusted Data vulnerability
Critical
CVE-2015-8103
was published
for
org.jenkins-ci.main:cli
(Maven)
May 13, 2022
Deserialization of Untrusted Data in Jenkins
Moderate
CVE-2017-1000355
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Race Condition in Jenkins
High
CVE-2017-1000503
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Cross-Site Request Forgery in Jenkins
High
CVE-2017-1000504
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Apache Tomcat vulnerable to SecurityManager bypass
High
CVE-2016-6796
was published
for
org.apache.tomcat:tomcat
(Maven)
May 13, 2022
Improper Handling of Exceptional Conditions in Apache Tomcat
High
CVE-2017-5664
was published
for
org.apache.tomcat:tomcat
(Maven)
May 13, 2022
Cloud Foundry UAA open redirect
Moderate
CVE-2018-11041
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 14, 2022
Cloud Foundry UAA accepts refresh token as access token on admin endpoints
High
CVE-2018-11047
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 13, 2022
Pivotal Cloud Foundry UAA XSS on UAA OpenID Connect check session iframe endpoint
Moderate
CVE-2018-1190
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 13, 2022
Cloud Foundry UAA SessionID present in Audit Event Logs
High
CVE-2018-1192
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 14, 2022
UAA privilege escalation across identity zones
High
CVE-2018-1262
was published
for
org.cloudfoundry.identity:cloudfoundry-identity-server
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API