GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,109
Maven
5,000+
npm
3,765
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
887
Swift
37
Unreviewed advisories
All unreviewed
5,000+
267 advisories
Filter by severity
Path traversal in Jenkins Job Configuration History Plugin
Moderate
CVE-2023-41930
was published
for
org.jenkins-ci.plugins:jobConfigHistory
(Maven)
Sep 6, 2023
pf4j vulnerable to remote code execution via expandIfZip method in the extract function
High
CVE-2023-40828
was published
for
org.pf4j:pf4j
(Maven)
Aug 29, 2023
pf4j vulnerable to remote code execution via loadpluginPath parameter
High
CVE-2023-40827
was published
for
org.pf4j:pf4j
(Maven)
Aug 29, 2023
pf4j vulnerable to remote code execution via the zippluginPath parameter
High
CVE-2023-40826
was published
for
org.pf4j:pf4j
(Maven)
Aug 29, 2023
Arbitrary File Creation in AbstractUnArchiver
High
CVE-2023-37460
was published
for
org.codehaus.plexus:plexus-archiver
(Maven)
Jul 25, 2023
Path Traversal in Apache Shiro
Critical
CVE-2023-34478
was published
for
org.apache.shiro:shiro-web
(Maven)
Jul 24, 2023
OpenRefine vulnerable to zip slip in project import
Moderate
CVE-2023-37476
was published
for
org.openrefine:main
(Maven)
Jul 18, 2023
Jenkins MathWorks Polyspace Plugin vulnerable to arbitrary file read
Moderate
CVE-2023-37960
was published
for
com.mathworks.polyspace.jenkins:mathworks-polyspace
(Maven)
Jul 12, 2023
Apache MINA SSHD information disclosure vulnerability
Moderate
CVE-2023-35887
was published
for
org.apache.sshd:sshd-common
(Maven)
Jul 10, 2023
Graylog server has partial path traversal vulnerability in Support Bundle feature
Low
CVE-2023-41044
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
Apache StreamPark Path Traversal vulnerability
Critical
CVE-2022-45802
was published
for
org.apache.streampark:streampark-common_2.11
(Maven)
Jul 6, 2023
Apache Linkis Zip Slip issue
Critical
CVE-2023-27603
was published
for
org.apache.linkis:linkis
(Maven)
Jul 6, 2023
hawtio vulnerable to Path Traversal
Moderate
CVE-2023-33544
was published
for
io.hawt:project
(Maven)
Jun 1, 2023
Administration Console authentication bypass in openfire xmppserver
High
CVE-2023-32315
was published
for
org.igniterealtime.openfire:xmppserver
(Maven)
May 23, 2023
Jenkins Code Dx Plugin missing permission checks
Moderate
CVE-2023-2196
was published
for
org.jenkins-ci.plugins:codedx
(Maven)
May 16, 2023
Jenkins Sidebar Link Plugin vulnerable to Path Traversal
Moderate
CVE-2023-32985
was published
for
org.jenkins-ci.plugins:sidebar-link
(Maven)
May 16, 2023
HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057
High
CVE-2023-28465
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Mar 10, 2023
Arbitrary file deletion in ureport
Critical
CVE-2023-24188
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Feb 13, 2023
StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route
Moderate
CVE-2023-24815
was published
for
io.vertx:vertx-web
(Maven)
Feb 10, 2023
Path Traversal In Eclipse GlassFish
Moderate
CVE-2022-2712
was published
for
org.glassfish.main.web:web
(Maven)
Jan 27, 2023
Path Traversal in Jenkins visualexpert Plugin
Moderate
CVE-2023-24455
was published
for
io.jenkins.plugins:visualexpert
(Maven)
Jan 26, 2023
Path traversal vulnerability in Jenkins PWauth Security Realm Plugin
Moderate
CVE-2023-24449
was published
for
org.jvnet.hudson.plugins:pwauth
(Maven)
Jan 26, 2023
MITM based Zip Slip in `ca.uhn.hapi.fhir:org.hl7.fhir.core`
Critical
CVE-2023-24057
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Jan 23, 2023
org.neo4j.procedure:apoc Path Traversal Vulnerability
High
CVE-2022-23532
was published
for
org.neo4j.procedure:apoc
(Maven)
Jan 13, 2023
Gravitee API Management contains Path Traversal
High
CVE-2022-38723
was published
for
io.gravitee.apim:gravitee-api-management
(Maven)
Jan 4, 2023
ProTip!
Advisories are also available from the
GraphQL API