An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

Moderate
4 months ago

Jenkins Missing Permission Check GSA_kwCzR0hTQS13cjZ3LWp4ZzctcXBmaM4ABGVY

maven org.jenkins-ci.main:jenkins-core
Moderate
4 months ago

Jenkins Missing Permission Check GSA_kwCzR0hTQS01NjVyLXBmNXEtNDV2Ns4ABGVN

maven org.jenkins-ci.main:jenkins-core
Moderate
5 months ago

Jenkins Open Redirect vulnerability GSA_kwCzR0hTQS04aG12LTkyd20tMzljaM4ABFJP

maven org.jenkins-ci.main:jenkins-core
High
12 months ago

Jenkins Remoting library arbitrary file read vulnerability GSA_kwCzR0hTQS1oODU2LWZmdnYteHZyNM4AA-cu

maven org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:remoting
High
almost 2 years ago

Jenkins Cross-site Scripting vulnerability GSA_kwCzR0hTQS01ajQ2LTVod3EtZ3doN84AA1-J

maven org.jenkins-ci.main:jenkins-core
High
about 2 years ago

Jenkins Stored Cross-site Scripting vulnerability GSA_kwCzR0hTQS02OXZ3LTNwY20tODRyd84AA05m

maven org.jenkins-ci.main:jenkins-core
High
about 2 years ago

Jenkins CSRF protection bypass vulnerability GSA_kwCzR0hTQS05OGZwLXIyMmctd3BqN84AAz2W

maven org.jenkins-ci.main:jenkins-core
Moderate
over 2 years ago

Denial of service in Jenkins Core GSA_kwCzR0hTQS1mcmdyLWM1ZjItOHFoaM4AAyCc

maven org.jenkins-ci.main:jenkins-core
Moderate
over 2 years ago

Incorrect Permission Preservation in Jenkins Core GSA_kwCzR0hTQS1jajZyLThweGotNWp2Ns4AAyCF

maven org.jenkins-ci.main:jenkins-core
Low
over 2 years ago

Incorrect Authorization in Jenkins Core GSA_kwCzR0hTQS01ODRtLTdyNG0tOGo2ds4AAyCI

maven org.jenkins-ci.main:jenkins-core
High
over 2 years ago

Incorrect Authorization in Jenkins Core GSA_kwCzR0hTQS1oZjloLXZ2NG0tMmYzM84AAyCn

maven org.jenkins-ci.main:jenkins-core
High
over 2 years ago

Cross-site Scripting vulnerability in Jenkins GSA_kwCzR0hTQS1qNjY0LXFoaDQtaHBmOM4AAyCa

maven org.jenkins-ci.main:jenkins-core
High
over 2 years ago

Denial of service in Jenkins Core GSA_kwCzR0hTQS1oNzZwLW1jNjgtanYzcM4AAyCk

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Cross-site Scripting vulnerability in Jenkins GSA_kwCzR0hTQS02MndmLTI0YzQtOHI3Ns4AAs8i

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Cross-site Scripting vulnerability in Jenkins GSA_kwCzR0hTQS02ZzRyLXE3cWctNnF4Ns4AAs8p

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Cross-site Scripting vulnerability in Jenkins GSA_kwCzR0hTQS03Zjg0LXA2cjUtanI2cc4AAs8h

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Cross-site Scripting vulnerability in Jenkins GSA_kwCzR0hTQS1taHA3LTMzOTMtcGZxcs4AAs8g

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Unauthorized view fragment access in Jenkins GSA_kwCzR0hTQS1wM3JjLTk0NmgtOGNmNc4AAs8u

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

Path traversal vulnerability on Windows in Jenkins GSA_kwCzR0hTQS00cHc1LXI1OGgtZnYyNM4AAqOh

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Session fixation vulnerability in Jenkins GSA_kwCzR0hTQS00d3I5LTJ4YzYtam1nNc4AAo_q

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

View name validation bypass in Jenkins GSA_kwCzR0hTQS13Mmh2LXJjcXItMmg3cs4AAoE2

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

Stored XSS vulnerability in Jenkins on new item page GSA_kwCzR0hTQS1tajdxLWNtZjMtbWc3aM4AAnOV

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

XSS vulnerability in Jenkins notification bar GSA_kwCzR0hTQS05OGdxLTZoeGctNTJyNs4AAnOI

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

Stored XSS vulnerability in Jenkins button labels GSA_kwCzR0hTQS13djYzLWd3cjktNWM1Nc4AAnOM

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Stored XSS vulnerability in Jenkins upstream cause GSA_kwCzR0hTQS1nNGo2LW0zbTMtY3J3OM4AAlYJ

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Stored XSS vulnerability in Jenkins console links GSA_kwCzR0hTQS1nZmhqLTUyNHEtZ2Nybc4AAlYZ

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Cross-Site Request Forgery in Jenkins GSA_kwCzR0hTQS1jNzM1LWc5ZjItMm12cM4AAkDI

maven org.jenkins-ci.main:jenkins-core
Low
about 3 years ago

Jenkins REST APIs vulnerable to clickjacking GSA_kwCzR0hTQS03eHA4LTd3cXgtNWhxeM4AAjcV

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

Non-constant time HMAC comparison GSA_kwCzR0hTQS1majZmLTY5MzMtODM5as4AAjcN

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

Jenkins Diagnostic page exposed session cookies GSA_kwCzR0hTQS00ampqLWNtN3EtdjZocs4AAjcO

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

XML external entity (XXE) vulnerability in Jenkins GSA_kwCzR0hTQS1xZzd4LTRoNHEtM200Oc4AAjQr

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

XML external entity (XXE) vulnerability in Jenkins GSA_kwCzR0hTQS1xajI3LXc5MmgtZmM5cs4AAjQo

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Cross-Site Request Forgery in Jenkins GSA_kwCzR0hTQS12Y3I4LWg4cXAtcWo4aM4AAh6e

maven org.jenkins-ci.main:jenkins-core
High
about 3 years ago

Cross-Site Request Forgery in Jenkins GSA_kwCzR0hTQS1oY3hmLXJxNzItaDRycs4AAhUU

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

Missing Authorization in Jenkins GSA_kwCzR0hTQS02amZjLW1jOTctYzd3Z84AAhUt

maven org.kohsuke.stapler:stapler-parent, org.jenkins-ci.main:jenkins-core
Low
about 3 years ago

Jenkins allows Cross-Site Scripting (XSS) GSA_kwCzR0hTQS1xM3JwLTU1NXItaGg2cs4AAdUF

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

Jenkins allows Remote Attackers to Hijack Sessions GSA_kwCzR0hTQS05YzI2LWNmOGMtbXc0M84AAdUB

maven org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago

Jenkins allows attackers to execute arbitrary jobs GSA_kwCzR0hTQS03ZnBnLXBwM20taDIyZs4AAdTl

maven org.jenkins-ci.main:jenkins-core

Filter by Severity

Filter by Ecosystem

Filter by Package

tensorflow 433 tensorflow-gpu 427 tensorflow-cpu 423 moodle/moodle 418 magento/community-edition 300 Microsoft.ChakraCore 247 org.jenkins-ci.main:jenkins-core 239 typo3/cms 190 org.apache.tomcat:tomcat 138 pimcore/pimcore 120 dolibarr/dolibarr 116 github.com/mattermost/mattermost/server/v8 115 typo3/cms-core 111 com.liferay.portal:release.portal.bom 110 phpmyadmin/phpmyadmin 107 Django 107 com.liferay.portal:release.dxp.bom 105 drupal/core 103 magento/project-community-edition 100 microweber/microweber 99 silverstripe/framework 92 apache-airflow 85 drupal/drupal 83 librenms/librenms 82 thorsten/phpmyfaq 73 Plone 72 symfony/symfony 69 com.fasterxml.jackson.core:jackson-databind 69 concrete5/concrete5 65 github.com/usememos/memos 65 salt 65 ansible 63 actionpack 61 shopware/platform 57 apache-superset 57 org.apache.struts:struts2-core 57 github.com/grafana/grafana 56 mlflow 53 craftcms/cms 51 org.keycloak:keycloak-core 50 nova 48 baserproject/basercms 47 django 46 nokogiri 46 org.apache.tomcat.embed:tomcat-embed-core 46 shopware/core 45 mautic/core 44 github.com/rancher/rancher 44 vyper 44 gradio 44 matrix-synapse 42 nilsteampassnet/teampass 42 rdiffweb 42 plone 41 org.keycloak:keycloak-services 41 k8s.io/kubernetes 41 org.xwiki.platform:xwiki-platform-oldcore 41 org.elasticsearch:elasticsearch 41 mantisbt/mantisbt 41 showdoc/showdoc 41 github.com/hashicorp/vault 40 froxlor/froxlor 40 intelliants/subrion 39 github.com/mattermost/mattermost-server/v6 39 directus 38 com.thoughtworks.xstream:xstream 37 snipe/snipe-it 36 com.jfinal:jfinal 36 net.mingsoft:ms-mcms 36 moin 35 org.jenkins-ci.plugins:script-security 34 zendframework/zendframework1 34 github.com/answerdev/answer 34 io.undertow:undertow-core 34 parse-server 33 gogs.io/gogs 33 keystone 32 github.com/cilium/cilium 31 opencv-contrib-python 31 Pillow 31 github.com/argoproj/argo-cd 31 github.com/argoproj/argo-cd/v2 31 github.com/hashicorp/nomad 31 opencv-python 31 shopware/shopware 30 getgrav/grav 30 github.com/mattermost/mattermost-server 29 rack 29 github.com/docker/docker 29 github.com/hashicorp/consul 29 mediawiki/core 28 org.apache.solr:solr-core 28 electron 28 org.opencms:opencms-core 27 centreon/centreon 27 prestashop/prestashop 26 pillow 26 openssl-src 26 org.springframework.security:spring-security-core 26 next 26 rubygems-update 25 org.eclipse.jetty:jetty-server 25 contao/core-bundle 25 open-webui 25 pocketmine/pocketmine-mp 24 github.com/traefik/traefik/v2 24 org.keycloak:keycloak-parent 24 getkirby/cms 24 magento/core 24 surrealdb 24 grumpydictator/firefly-iii 23 simplesamlphp/simplesamlphp 23 phpoffice/phpexcel 23 laravel/framework 23 remdex/livehelperchat 23 puppet 23 zendframework/zendframework 23 vllm 23 Microsoft.AspNetCore.App.Runtime.win-x64 22 tribalsystems/zenario 22 org.bouncycastle:bcprov-jdk14 22 @openzeppelin/contracts-upgradeable 22 org.apache.openmeetings:openmeetings-parent 22 ckb 22 DotNetNuke.Core 22 Microsoft.AspNetCore.App.Runtime.win-x86 22 phpoffice/phpspreadsheet 21 activerecord 21 @openzeppelin/contracts 21 github.com/goharbor/harbor 21 github.com/ethereum/go-ethereum 21 org.apache.nifi:nifi 21 glance 21 Microsoft.AspNetCore.App.Runtime.win-arm 21 org.apache.tomcat:tomcat-catalina 21 org.cloudfoundry.identity:cloudfoundry-identity-server 20 aim 20 wasmtime 20 code.gitea.io/gitea 20 funadmin/funadmin 20 cockpit-hq/cockpit 20 golang.org/x/net 20 langchain 20 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 19 org.apache.tomcat:tomcat-coyote 19 github.com/zitadel/zitadel 19 org.xwiki.platform:xwiki-platform-web-templates 19 helm.sh/helm/v3 19 Microsoft.AspNetCore.App.Runtime.linux-arm64 19 Microsoft.AspNetCore.App.Runtime.linux-x64 19 Microsoft.AspNetCore.App.Runtime.osx-x64 19 Microsoft.AspNetCore.App.Runtime.win-arm64 19 pyload-ng 19 Microsoft.AspNetCore.App.Runtime.linux-arm 19 deno 19 neutron 19 topthink/framework 18 com.vaadin:vaadin-bom 18 genix/cms 18 cobbler 18 forkcms/forkcms 18 contao/contao 18 mercurial 18 mindsdb 18 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 18 opencart/opencart 17 cryptography 17 typo3/cms-backend 17 org.springframework:spring-core 17 cakephp/cakephp 17 openmage/magento-lts 17 calibreweb 17 yetiforce/yetiforce-crm 17 org.apache.geode:geode-core 17 ezsystems/ezpublish-kernel 17 notebook 17 OctoPrint 17 symfony/security 17 francoisjacquet/rosariosis 17 org.apache.inlong:manager-pojo 17 paddlepaddle 16 org.apache.jspwiki:jspwiki-main 16 org.bouncycastle:bcprov-jdk15 16 org.apache.ranger:ranger 16 org.apache.activemq:activemq-client 16 rusqlite 16 Microsoft.NetCore.App.Runtime.win-x86 16 Microsoft.NetCore.App.Runtime.win-x64 16 tinymce 16 Microsoft.NetCore.App.Runtime.win-arm64 16 Microsoft.NetCore.App.Runtime.win-arm 16 lollms 16 sequelize 16 phpbb/phpbb 16 org.apache.dubbo:dubbo 16 github.com/traefik/traefik/v3 16 october/system 16 ethyca-fides 16 PaddlePaddle 16 github.com/openfga/openfga 16

Filter by Repository