GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            33 advisories
        Filter by severity
        
      
      
    
                    
                      Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
                    
                      
  Critical
                    
                
                      
                        CVE-2025-24813
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      Mar 10, 2025 
                    
                  
                    
                      Sandbox bypass in Jenkins Pipeline: Groovy Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2019-1003030
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins.workflow:workflow-cps
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      Sandbox bypass in Script Security Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2019-1003029
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:script-security
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      Apache Tomcat Improper Access Control vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2016-8735
                      
                      was published
                        for
                        
                          org.apache.tomcat:tomcat-catalina
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      HTTP Request Smuggling in Netty
                    
                      
  Critical
                    
                
                      
                        CVE-2019-20444
                      
                      was published
                        for
                        
                          io.netty:netty
                        
                        (Maven)
                      Feb 21, 2020 
                    
                  
                    
                      Expected Behavior Violation in Apache Tomcat
                    
                      
  Critical
                    
                
                      
                        CVE-2017-5651
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      Exposure of Resource to Wrong Sphere in Apache Tomcat
                    
                      
  Critical
                    
                
                      
                        CVE-2017-5648
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
                    
                      
  Critical
                    
                
                      
                        CVE-2016-5018
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-jasper
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
                    
                      
  Critical
                    
                
                      
                        CVE-2021-21685
                      
                      was published
                        for
                        
                          org.jenkins-ci.main:jenkins-core
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Deserialization of Untrusted Data in jackson-databind
                    
                      
  Critical
                    
                
                      
                        CVE-2019-20330
                      
                      was published
                        for
                        
                          com.fasterxml.jackson.core:jackson-databind
                        
                        (Maven)
                      Mar 4, 2020 
                    
                  
                    
                      Unsafe entry in Script Security list of approved signatures in Pipeline Remote Loader Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2019-10328
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:workflow-remote-loader
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Script security sandbox bypass in Jenkins Job DSL Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2019-1003034
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:job-dsl
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      Script security sandbox bypass in Matrix Project Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2019-1003031
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:matrix-project
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      Improper Authentication (empty password) in Jenkins Active Directory Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2020-2300
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:active-directory
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2019-1003041
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins.workflow:workflow-cps
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      Sandbox bypass vulnerability in Jenkins Script Security Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2019-1003040
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:script-security
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      XXE vulnerability in Jenkins Generic Webhook Trigger Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2021-21669
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:generic-webhook-trigger
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Authentication cache in Active Directory Jenkins Plugin allows logging in with any password
                    
                      
  Critical
                    
                
                      
                        CVE-2020-2301
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:active-directory
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Improper Authentication in Jenkins Active Directory Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2020-2299
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:active-directory
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Sandbox bypass vulnerability in Jenkins Script Security Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2020-2279
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:script-security
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Sandbox bypass in ontrack Jenkins Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2019-10306
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:ontrack
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
                    
                      
  Critical
                    
                
                      
                        CVE-2021-21686
                      
                      was published
                        for
                        
                          org.jenkins-ci.main:jenkins-core
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Remote code execution in handlebars when compiling templates
                    
                      
  Critical
                    
                
                      
                        CVE-2021-23369
                      
                      was published
                        for
                        
                          handlebars
                        
                        (Maven)
                      May 6, 2021 
                    
                  
                    
                      XML external entity vulnerability in Jenkins Nuget Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2021-21658
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:nuget
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Jenkins Plugin Installation Manager Tool did not verify plugin downloads
                    
                      
  Critical
                    
                
                      
                        CVE-2020-2320
                      
                      was published
                        for
                        
                          io.jenkins.plugin-management:plugin-management-parent-pom
                        
                        (Maven)
                      May 24, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API