GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
137 advisories
Filter by severity
Missing permission check in Jenkins Dimensions Plugin allows enumerating credentials IDs
Moderate
CVE-2023-32261
was published
for
org.jenkins-ci.plugins:dimensionsscm
(Maven)
Jul 19, 2023
Spring Security's authorization rules can be misconfigured when using multiple servlets
High
CVE-2023-34035
was published
for
org.springframework.security:spring-security-config
(Maven)
Jul 18, 2023
Apache Pulsar Function Worker Incorrect Authorization vulnerability
Moderate
CVE-2023-37579
was published
for
org.apache.pulsar:pulsar-functions-worker
(Maven)
Jul 12, 2023
Apache Pulsar Incorrect Authorization vulnerability
Critical
CVE-2023-30429
was published
for
org.apache.pulsar:pulsar
(Maven)
Jul 12, 2023
Apache Pulsar Broker's Rest Producer vulnerable to Incorrect Authorization
High
CVE-2023-30428
was published
for
org.apache.pulsar:pulsar-broker
(Maven)
Jul 12, 2023
XWiki Platform vulnerable to privilege escalation (PR) from account through TipsPanel
High
CVE-2023-35166
was published
for
org.xwiki.platform:xwiki-platform-help-ui
(Maven)
Jun 20, 2023
Privilege escalation (PR)/RCE from account through class sheet
Critical
CVE-2023-32069
was published
for
org.xwiki.platform:xwiki-platform-test-ui
(Maven)
May 11, 2023
OpenSearch issue with fine-grained access control during extremely rare race conditions
Moderate
CVE-2023-31141
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
May 9, 2023
Incorrect Authorization in Jenkins Core
Low
CVE-2023-27903
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
Incorrect Authorization in Jenkins Core
High
CVE-2023-27899
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
OpenSearch has issue with fine-grained access control of indices backing data streams
Moderate
CVE-2022-41918
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Mar 7, 2023
xwiki contains Incorrect Authorization
Moderate
CVE-2023-26056
was published
for
org.xwiki.platform:xwiki-platform-rendering-macro-context
(Maven)
Mar 3, 2023
Missing Authorization in Jenkins Azure Credentials Plugin
Moderate
CVE-2023-25768
was published
for
org.jenkins-ci.plugins:azure-credentials
(Maven)
Feb 15, 2023
Keycloak has lack of validation of access token on client registrations endpoint
Moderate
CVE-2023-0091
was published
for
org.keycloak:keycloak-core
(Maven)
Jan 12, 2023
Incorrect permission checks in Jenkins Support Core Plugin
Moderate
CVE-2022-45383
was published
for
org.jenkins-ci.plugins:support-core
(Maven)
Nov 16, 2022
Spring Security authorization rules can be bypassed via forward or include dispatcher types
Critical
CVE-2022-31692
was published
for
org.springframework.security:spring-security-core
(Maven)
Nov 1, 2022
Missing permission check in Jenkins build-publisher Plugin
Moderate
CVE-2022-41230
was published
for
org.jenkins-ci.plugins:build-publisher
(Maven)
Sep 22, 2022
Pebble Templates protection mechanism bypass can lead to arbitrary code execution
Critical
CVE-2022-37767
was published
for
io.pebbletemplates:pebble
(Maven)
Sep 13, 2022
XMLUI's metadata of withdrawn Items is exposed to anonymous users
Moderate
CVE-2022-31190
was published
for
org.dspace:dspace-xmlui
(Maven)
Aug 6, 2022
UnsafeAccessor 1.4.0 until 1.7.0 has no security checking for UnsafeAccess.getInstance()
Moderate
CVE-2022-31139
was published
for
io.github.karlatemp:unsafe-accessor
(Maven)
Jul 12, 2022
Incorrect Authorization in Jenkins Request Rename Or Delete Plugin
Moderate
CVE-2022-34814
was published
for
org.jenkins-ci.plugins:rrod
(Maven)
Jul 1, 2022
Incorrect Authorization in Jenkins requests-plugin
Moderate
CVE-2022-34782
was published
for
org.jenkins-ci.plugins:requests
(Maven)
Jul 1, 2022
Improper Authorization in Apache Shiro
Critical
CVE-2022-32532
was published
for
org.apache.shiro:shiro-core
(Maven)
Jun 30, 2022
NT auth module vulnerability in OpenAM
Moderate
CVE-2022-34298
was published
for
org.openidentityplatform.openam:openam-core
(Maven)
Jun 24, 2022
Unauthorized view fragment access in Jenkins
High
CVE-2022-34175
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 24, 2022
ProTip!
Advisories are also available from the
GraphQL API