GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,064
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
143 advisories
Filter by severity
Cross-Site Request Forgery in Jenkins Recipe Plugin
High
CVE-2022-34792
was published
for
org.jenkins-ci.plugins:recipe
(Maven)
Jul 1, 2022
Cross Site Request Forgery in Mingsoft MCMS
High
CVE-2022-29647
was published
for
net.mingsoft:ms-mcms
(Maven)
Jun 3, 2022
Jenkins SAML Plugin allows bypassing CSRF protection for any URL
High
CVE-2021-21678
was published
for
org.jenkins-ci.plugins:saml
(Maven)
May 24, 2022
Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL
High
CVE-2021-21679
was published
for
org.jenkins-ci.plugins:azure-ad
(Maven)
May 24, 2022
Cross-Site Request Forgery in OWASP CSRFGuard
High
CVE-2021-28490
was published
for
org.owasp:csrfguard
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials
High
CVE-2021-21665
was published
for
com.xebialabs.deployit.ci:deployit-plugin
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Team Foundation Server Plugin allow capturing credentials
High
CVE-2021-21638
was published
for
org.jenkins-ci.plugins:tfs
(Maven)
May 24, 2022
CSRF vulnerability and in Jenkins OWASP Dependency-Track Plugin allow capturing credentials
High
CVE-2021-21633
was published
for
org.jenkins-ci.plugins:dependency-track
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Build With Parameters Plugin
High
CVE-2021-21629
was published
for
org.jenkins-ci.plugins:build-with-parameters
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Libvirt Agents Plugin
High
CVE-2021-21627
was published
for
org.jenkins-ci.plugins:libvirt-slave
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Configuration Slicing Plugin
High
CVE-2021-21617
was published
for
org.jenkins-ci.plugins:configurationslicing
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Shelve Project Plugin
High
CVE-2020-2321
was published
for
org.jenkins-ci.plugins:shelve-project-plugin
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins warnings Plugin allows remote code execution
High
CVE-2020-2280
was published
for
org.jvnet.hudson.plugins:warnings
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Database Plugin
High
CVE-2020-2240
was published
for
org.jenkins-ci.plugins:database
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Pipeline Maven Integration Plugin allow capturing credentials
High
CVE-2020-2235
was published
for
org.jenkins-ci.plugins:pipeline-maven
(Maven)
May 24, 2022
Complete lack of CSRF protection in Jenkins Selenium Plugin can lead to OS command injection
High
CVE-2020-2196
was published
for
org.jenkins-ci.plugins:selenium
(Maven)
May 24, 2022
Cross-Site Request Forgery in Jenkins
High
CVE-2020-2160
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
CSRF vulnerability in Pipeline GitHub Notify Step Plugin allows capturing credentials
High
CVE-2020-2116
was published
for
org.jenkins-ci.plugins:pipeline-githubnotify-step
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Sounds Plugin allow OS command execution
High
CVE-2020-2098
was published
for
org.jenkins-ci.plugins:sounds
(Maven)
May 24, 2022
Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin
High
CVE-2019-16575
was published
for
io.alauda.jenkins.plugins:alauda-kubernetes-support
(Maven)
May 24, 2022
Jenkins Alauda DevOps Pipeline Plugin vulnerable to cross-site request forgery
High
CVE-2019-16573
was published
for
com.alauda.jenkins.plugins:alauda-devops-pipeline
(Maven)
May 24, 2022
Cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin
High
CVE-2019-16560
was published
for
org.jenkins-ci.plugins:websphere-deployer
(Maven)
May 24, 2022
Jenkins Team Concert Plugin cross-site request forgery vulnerability
High
CVE-2019-16565
was published
for
org.jenkins-ci.plugins:teamconcert
(Maven)
May 24, 2022
Cross-Site Request Forgery in Jenkins Build Failure Analyzer Plugin
High
CVE-2019-16553
was published
for
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
(Maven)
May 24, 2022
Cross-Site Request Forgery in Jenkins Gerrit Trigger Plugin
High
CVE-2019-16551
was published
for
com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API