GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,790
Erlang
36
GitHub Actions
29
Go
2,370
Maven
5,000+
npm
3,994
NuGet
720
pip
3,783
Pub
12
RubyGems
927
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
279 advisories
Filter by severity
Path Traversal in Gravitee API Management
Moderate
CVE-2019-25075
was published
for
io.gravitee.apim:gravitee-api-management
(Maven)
Aug 24, 2022
Path Traversal in Payara
High
CVE-2022-37422
was published
for
fish.payara.api:payara-bom
(Maven)
Aug 19, 2022
Venice vulnerable to Partial Path Traversal issue within the functions `load-file` and `load-resource`
Moderate
CVE-2022-36007
was published
for
com.github.jlangch:venice
(Maven)
Aug 18, 2022
Neo4j Graph apoc plugins Partial Path Traversal Vulnerability
Moderate
CVE-2022-37423
was published
for
org.neo4j.procedure:apoc
(Maven)
Aug 12, 2022
DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import
High
CVE-2022-31195
was published
for
org.dspace:dspace-api
(Maven)
Aug 6, 2022
JSPUI vulnerable to path traversal in submission (resumable) upload
High
CVE-2022-31194
was published
for
org.dspace:dspace-jspui
(Maven)
Aug 6, 2022
Jenkins Deployer Framework Plugin does not restrict application path of applications when configuring a deployment
Moderate
CVE-2022-36889
was published
for
org.jenkins-ci.plugins:deployer-framework
(Maven)
Jul 28, 2022
Jenkins Deployer Framework Plugin vulnerable to Path Traversal
Moderate
CVE-2022-36890
was published
for
org.jenkins-ci.plugins:deployer-framework
(Maven)
Jul 28, 2022
Arbitrary file write vulnerability in Jenkins CLIF Performance Testing plugin
High
CVE-2022-36894
was published
for
org.jenkins-ci.plugins:clif-performance-testing
(Maven)
Jul 28, 2022
Partial Path Traversal in com.amazonaws:aws-java-sdk-s3
High
CVE-2022-31159
was published
for
com.amazonaws:aws-java-sdk-s3
(Maven)
Jul 15, 2022
Arbitrary file write vulnerability in Jenkins Pipeline: Input Step Plugin
High
CVE-2022-34177
was published
for
org.jenkins-ci.plugins:pipeline-input-step
(Maven)
Jun 24, 2022
Cross-site Scripting vulnerability in Jenkins
High
CVE-2022-34172
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 24, 2022
Cross-site Scripting vulnerability in Jenkins
High
CVE-2022-34173
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 24, 2022
Cross-site Scripting vulnerability in Jenkins
High
CVE-2022-34171
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 24, 2022
Path Traversal vulnerability in Jenkins Embeddable Build Status Plugin
Moderate
CVE-2022-34179
was published
for
org.jenkins-ci.plugins:embeddable-build-status
(Maven)
Jun 24, 2022
Cross-site Scripting vulnerability in Jenkins
High
CVE-2022-34170
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 24, 2022
User account escalation in Apache Hadoop
High
CVE-2021-33036
was published
for
org.apache.hadoop:hadoop-yarn-server-common
(Maven)
Jun 16, 2022
Path Traversal in XWiki Platform
Low
CVE-2022-29253
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 1, 2022
Path traversal in CureKit
High
CVE-2022-23082
was published
for
io.whitesource:curekit
(Maven)
Jun 1, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21686
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21692
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21690
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files
Moderate
CVE-2021-21698
was published
for
org.jenkins-ci.plugins:subversion
(Maven)
May 24, 2022
Path traversal vulnerability on Windows in Jenkins
Moderate
CVE-2021-21683
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client
High
CVE-2021-20218
was published
for
io.fabric8:kubernetes-client
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API