GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,426
Erlang
29
GitHub Actions
16
Go
1,653
Maven
4,915
npm
3,442
NuGet
594
pip
2,832
Pub
10
RubyGems
823
Rust
763
Swift
34
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership,...
Low
Unreviewed
CVE-2016-1773
was published
May 17, 2022
The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to...
Critical
Unreviewed
CVE-2016-0788
was published
May 14, 2022
Exposure of Sensitive Information in Jenkins Core
Moderate
CVE-2016-0790
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS...
Moderate
Unreviewed
CVE-2016-0789
was published
May 14, 2022
Exposure of Sensitive Information in Jenkins Core
Critical
CVE-2016-0791
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote...
High
Unreviewed
CVE-2016-0792
was published
May 14, 2022
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject...
Moderate
Unreviewed
CVE-2016-3721
was published
May 14, 2022
Exposure of Sensitive Information in Jenkins Core
Moderate
CVE-2016-3723
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read...
Moderate
Unreviewed
CVE-2016-3724
was published
May 14, 2022
Incorrect Authorization in Jenkins Core
Moderate
CVE-2016-3722
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote...
High
Unreviewed
CVE-2016-3726
was published
May 14, 2022
Missing permissions check in Jenkins Core
Moderate
CVE-2016-3725
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote...
Moderate
Unreviewed
CVE-2016-3727
was published
May 14, 2022
Deserialization of Untrusted Data in Apache commons collections
Critical
CVE-2015-7501
was published
for
commons-collections:commons-collections
(Maven)
May 13, 2022
Improper Verification of Cryptographic Signature in org.apache.httpcomponents:httpclient
Moderate
CVE-2014-3577
was published
for
org.apache.httpcomponents:httpclient
(Maven)
Oct 17, 2018
ProTip!
Advisories are also available from the
GraphQL API