GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,965
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
134 advisories
Filter by severity
Jetty Directory Traversal Vulnerability
Moderate
CVE-2006-2758
was published
for
org.mortbay.jetty:jetty
(Maven)
May 1, 2022
Apache Tomcat Directory Traversal
Moderate
CVE-2000-1210
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 30, 2022
Jakarta Tomcat Directory Listing vulnerability
Moderate
CVE-2003-0042
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 29, 2022
Arbitrary file read vulnerability in Jenkins Continuous Integration with Toad Edge Plugin
Moderate
CVE-2022-28146
was published
for
org.jenkins-ci.plugins:ci-with-toad-edge
(Maven)
Mar 30, 2022
Path traversal in Jenkins Phoenix AutoTest Plugin
Moderate
CVE-2022-28156
was published
for
com.surenpi.jenkins:phoenix-autotest
(Maven)
Mar 30, 2022
Path traversal vulnerability on Windows in Jenkins Continuous Integration with Toad Edge Plugin
Moderate
CVE-2022-28148
was published
for
org.jenkins-ci.plugins:ci-with-toad-edge
(Maven)
Mar 30, 2022
Path traversal in Jenkins Pipeline Phoenix AutoTest Plugin
Moderate
CVE-2022-28157
was published
for
com.surenpi.jenkins:phoenix-autotest
(Maven)
Mar 30, 2022
Path Traversal in Spring-integration-zip
Moderate
CVE-2021-22114
was published
for
org.springframework.integration:spring-integration-zip
(Maven)
Mar 18, 2022
Arbitrary JSON and property file read vulnerability in Jenkins Extended Choice Parameter Plugin
Moderate
CVE-2022-27203
was published
for
org.jenkins-ci.plugins:extended-choice-parameter
(Maven)
Mar 16, 2022
Arbitrary file read vulnerability in Jenkins kubernetes-cd Plugin
Moderate
CVE-2022-27208
was published
for
org.jenkins-ci.plugins:kubernetes-cd
(Maven)
Mar 16, 2022
Path Traversal in LemMinX
Moderate
CVE-2022-0673
was published
for
org.eclipse.lemminx:lemminx-parent
(Maven)
Feb 19, 2022
Improper Limitation of a Pathname to a Restricted Directory in Jenkins Pipeline: Shared Groovy Libraries Plugin
Moderate
CVE-2022-25178
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps-global-lib
(Maven)
Feb 16, 2022
Path traversal vulnerability in Jenkins Fortify Plugin
Moderate
CVE-2022-25188
was published
for
org.jenkins-ci.plugins:fortify
(Maven)
Feb 16, 2022
Path traversal in xwiki-platform-skin-skinx
Moderate
CVE-2022-23620
was published
for
org.xwiki.platform:xwiki-platform-skin-skinx
(Maven)
Feb 9, 2022
Path Traversal in Apache James Server
Moderate
CVE-2022-22931
was published
for
org.apache.james:james-server
(Maven)
Feb 8, 2022
Path traversal in Apache Karaf
Moderate
CVE-2022-22932
was published
for
org.apache.karaf:apache-karaf
(Maven)
Jan 28, 2022
Path traversal vulnerability in Jenkins Publish Over SSH Plugin
Moderate
CVE-2022-23113
was published
for
org.jenkins-ci.plugins:publish-over-ssh
(Maven)
Jan 13, 2022
StaticFile.fromUrl can leak presence of a directory
Moderate
CVE-2021-32643
was published
for
org.http4s:http4s-core
(Maven)
May 28, 2021
Path Traversal and Improper Input Validation in Apache Commons IO
Moderate
CVE-2021-29425
was published
for
com.cosium.vet:vet
(Maven)
Apr 26, 2021
Directory traversal in development mode handler in Vaadin 14 and 15-17
Moderate
CVE-2020-36321
was published
for
com.vaadin:flow-server
(Maven)
Apr 19, 2021
MPXJ path Traversal vulnerability
Moderate
CVE-2020-35460
was published
for
net.sf.mpxj:mpxj
(Maven)
Dec 18, 2020
Directory traversal in Apache RocketMQ
Moderate
CVE-2019-17572
was published
for
org.apache.rocketmq:rocketmq-broker
(Maven)
Jul 1, 2020
Directory traversal attack in Spring Cloud Config
Moderate
CVE-2020-5405
was published
for
org.springframework.cloud:spring-cloud-config-server
(Maven)
Jun 5, 2020
path traversal in Jooby
Moderate
CVE-2020-7647
was published
for
io.jooby:jooby
(Maven)
May 13, 2020
Local file inclusion allows unauthorized access to internal resources in Alkacon OpenCms
Moderate
CVE-2019-13237
was published
for
org.opencms:opencms-core
(Maven)
Nov 12, 2019
ProTip!
Advisories are also available from the
GraphQL API