GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            57 advisories
        Filter by severity
        
      
      
    
                    
                      Jenkins Testsigma Test Plan vulnerability exposes API keys via job configuration form
                    
                      
  Low
                    
                
                      
                        CVE-2025-53661
                      
                      was published
                        for
                        
                          io.jenkins.plugins:testsigma
                        
                        (Maven)
                      Jul 9, 2025 
                    
                  
                    
                      Jenkins Zoho QEngine Plugin Displays Unmasked API Keys
                    
                      
  Low
                    
                
                      
                        CVE-2025-30197
                      
                      was published
                        for
                        
                          io.jenkins.plugins:zohoqengine
                        
                        (Maven)
                      Mar 19, 2025 
                    
                  
                    
                      Jenkins Telegram Bot Plugin stores the Telegram Bot token in plaintext
                    
                      
  Low
                    
                
                      
                        CVE-2024-34147
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:telegrambot
                        
                        (Maven)
                      May 2, 2024 
                    
                  
                    
                      Jenkins NS-ND Integration Performance Publisher Plugin displays credentials without masking
                    
                      
  Low
                    
                
                      
                        CVE-2023-33000
                      
                      was published
                        for
                        
                          io.jenkins.plugins:cavisson-ns-nd-integration
                        
                        (Maven)
                      May 16, 2023 
                    
                  
                    
                      Jenkins BigPanda Notifier Plugin stores BigPanda API key unencrypted
                    
                      
  Low
                    
                
                      
                        CVE-2022-41247
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:bigpanda-jenkins
                        
                        (Maven)
                      Sep 22, 2022 
                    
                  
                    
                      API token stored in plain text by Jenkins CONS3RT Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-41255
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:cons3rt
                        
                        (Maven)
                      Sep 22, 2022 
                    
                  
                    
                      RabbitMQ password stored in plain text by Jenkins CollabNet Plugins Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-38665
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:collabnet
                        
                        (Maven)
                      Aug 24, 2022 
                    
                  
                    
                      Plaintext Storage of a Password in Jenkins Elasticsearch Query Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-34807
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:elasticsearch-query
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
                    
                      Plaintext Storage of a Password in Jenkins Jigomerge Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-34806
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:jigomerge
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
                    
                      Password stored in plain text by Jenkins RQM Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-34809
                      
                      was published
                        for
                        
                          net.praqma:rqm-plugin
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
                    
                      Passwords stored in plain text by Jenkins hpe-network-virtualization plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-34816
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:hpe-network-virtualization
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
                    
                      Plaintext Storage of a Password in Jenkins Skype notifier Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-34805
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:skype-notifier
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
                    
                      Token stored in plain text by Jenkins Cisco Spark Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-34808
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:cisco-spark
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
                    
                      Plaintext Storage of a Password in Jenkins Build Notifications Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-34800
                      
                      was published
                        for
                        
                          tools.devnull:build-notifications
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
                    
                      Plaintext Storage of a Password in Jenkins RocketChat Notifier Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-34802
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:rocketchatnotifier
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
                    
                      Plaintext Storage of a Password in Jenkins Deployment Dashboard Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-34799
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:ec2-deployment-dashboard
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
                    
                      Squash TM Publisher (Squash4Jenkins) Plugin stores passwords stored in plain text
                    
                      
  Low
                    
                
                      
                        CVE-2022-34213
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:squashtm-publisher
                        
                        (Maven)
                      Jun 24, 2022 
                    
                  
                    
                      Password stored in plain text by Jenkins VMware Lab Manager Slaves Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2020-2319
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:labmanager
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Password stored in plain text by Jenkins AppSpider Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2020-2314
                      
                      was published
                        for
                        
                          com.rapid7:jenkinsci-appspider-plugin
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Access token stored in plain text by Jenkins SMS Notification Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2020-2297
                      
                      was published
                        for
                        
                          com.hoiio.jenkins:sms
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Password stored in plain text by Jenkins couchdb-statistics Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2020-2291
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:couchdb-statistics
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Password stored in plain text by Jenkins HP ALM Quality Center Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2020-2218
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:hp-quality-center
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Improper masking of some secrets in Jenkins Credentials Binding Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2020-2182
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:credentials-binding
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Passwords stored in plain text by Jenkins Artifactory Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2020-2164
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:artifactory
                        
                        (Maven)
                      May 24, 2022 
                    
                  
                    
                      Passwords transmitted in plain text by Jenkins Artifactory Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2020-2165
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:artifactory
                        
                        (Maven)
                      May 24, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API