GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,946
Erlang
29
GitHub Actions
16
Go
1,734
Maven
4,963
npm
3,493
NuGet
607
pip
3,059
Pub
10
RubyGems
832
Rust
779
Swift
34
Unreviewed advisories
All unreviewed
5,000+
251 advisories
Filter by severity
Apache Tomcat XSS In Accept-Language Headers
Low
CVE-2007-1358
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Jenkins Repository Connector Plugin has insufficiently protected credentials
Low
CVE-2019-1003038
was published
for
org.jenkins-ci.plugins:repository-connector
(Maven)
May 13, 2022
Jenkins Aqua Security Scanner Plugin stores credentials in plain text
Low
CVE-2019-1003069
was published
for
org.jenkins-ci.plugins:aqua-security-scanner
(Maven)
May 13, 2022
Jenkins Octopus Deploy Plugin stores credentials in plain text
Low
CVE-2019-1003071
was published
for
hudson.plugins.octopusdeploy:octopusdeploy
(Maven)
May 13, 2022
Jenkins OWASP ZAP Plugin stores unencrypted credentials
Low
CVE-2019-1003060
was published
for
org.jenkins-ci.plugins:zap
(Maven)
May 13, 2022
Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials in plain text
Low
CVE-2019-1003052
was published
for
org.jenkins-ci.plugins:aws-beanstalk-publisher-plugin
(Maven)
May 13, 2022
Jenkins IRC Plugin stores credentials in plain text
Low
CVE-2019-1003051
was published
for
org.jvnet.hudson.plugins:ircbot
(Maven)
May 13, 2022
Jenkins Amazon SNS Build Notifier Plugin stores credentials in plain text
Low
CVE-2019-1003063
was published
for
org.jenkins-ci.plugins:snsnotify
(Maven)
May 13, 2022
Jenkins CloudShare Docker-Machine Plugin stores credentials in plain text
Low
CVE-2019-1003065
was published
for
org.jenkins-ci.plugins:cloudshare-docker
(Maven)
May 13, 2022
Jenkins FTP publisher Plugin stores credentials in plain text
Low
CVE-2019-1003055
was published
for
org.jvnet.hudson.plugins:ftppublisher
(Maven)
May 13, 2022
Jenkins Bitbucket Approve Plugin stores credentials in plain text
Low
CVE-2019-1003057
was published
for
org.jenkins-ci.plugins:bitbucket-approve
(Maven)
May 13, 2022
Jenkins Bugzilla Plugin stores credentials in plain text
Low
CVE-2019-1003066
was published
for
org.jvnet.hudson.plugins:bugzilla
(Maven)
May 13, 2022
Jenkins AWS CloudWatch Logs Publisher Plugin stores credentials in plain text
Low
CVE-2019-1003062
was published
for
org.jenkins-ci.plugins:aws-cloudwatch-logs-publisher
(Maven)
May 13, 2022
Jenkins aws-device-farm Plugin stores credentials in plain text
Low
CVE-2019-1003064
was published
for
org.jenkins-ci.plugins:aws-device-farm
(Maven)
May 13, 2022
Jenkins veracode-scanner Plugin stores credentials in plain text
Low
CVE-2019-1003070
was published
for
org.jenkins-ci.plugins:veracode-scanner
(Maven)
May 13, 2022
Jenkins Audit to Database Plugin stores credentials in plain text
Low
CVE-2019-1003075
was published
for
org.jenkins-ci.plugins:audit2db
(Maven)
May 13, 2022
Jenkins hyper.sh Commons Plugin stores credentials in plain text
Low
CVE-2019-1003074
was published
for
sh.hyper.plugins:hyper-commons
(Maven)
May 13, 2022
Jenkins PRQA Plugin stored password in plain text
Low
CVE-2019-1003048
was published
for
com.programmingresearch:prqa-plugin
(Maven)
May 13, 2022
Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials in plain text
Low
CVE-2019-10281
was published
for
org.jenkins-ci.plugins:relution-publisher
(Maven)
May 13, 2022
Jenkins Minio Storage Plugin stores credentials in plain text
Low
CVE-2019-10285
was published
for
org.jenkins-ci.plugins:minio-storage
(Maven)
May 13, 2022
Jenkins youtrack-plugin Plugin stored credentials in plain text
Low
CVE-2019-10287
was published
for
org.jenkins-ci.plugins:youtrack-plugin
(Maven)
May 13, 2022
Jenkins Jabber Server Plugin stores credentials in plain text
Low
CVE-2019-10288
was published
for
de.e-nexus:jabber-server-plugin
(Maven)
May 13, 2022
Jenkins CloudCoreo DeployTime Plugin stores credentials in plain text
Low
CVE-2019-10299
was published
for
com.cloudcoreo.plugins:cloudcoreo-deploytime
(Maven)
May 13, 2022
Jenkins Koji Plugin stores credentials in plain text
Low
CVE-2019-10298
was published
for
org.jenkins-ci.plugins:koji
(Maven)
May 13, 2022
Jenkins Sametime Plugin stores credentials in plain text
Low
CVE-2019-10297
was published
for
org.jenkins-ci.plugins:sametime
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API