Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

385 advisories

Loading
Jenkins Zowe zDevOps Plugin has a missing permission check Moderate
CVE-2026-57307 was published for io.jenkins.plugins:zdevops (Maven) Jun 24, 2026
Jenkins Assembla Plugin has a missing permission check Moderate
CVE-2026-57304 was published for org.jenkins-ci.plugins:assembla (Maven) Jun 24, 2026
Jenkins MCP Server Plugin missing a permission check Moderate
CVE-2026-57300 was published for io.jenkins.plugins:mcp-server (Maven) Jun 24, 2026
Jenkins Contrast Continuous Application Security Plugin missing permission checks Moderate
CVE-2026-57299 was published for org.jenkins-ci.plugins:contrast-continuous-application-security (Maven) Jun 24, 2026
Jenkins Gitee Plugin missing permission checks Moderate
CVE-2026-57291 was published for org.jenkins-ci.plugins:gitee (Maven) Jun 24, 2026
Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs Moderate
CVE-2026-57293 was published for org.jenkins-ci.plugins:gitee (Maven) Jun 24, 2026
Jenkins EC2 Fleet Plugin has a missing permission check Moderate
CVE-2026-57294 was published for com.amazon.jenkins.fleet:ec2-fleet (Maven) Jun 24, 2026
Jenkins Contrast Continuous Application Security Plugin has a missing permission check Moderate
CVE-2026-57297 was published for org.jenkins-ci.plugins:contrast-continuous-application-security (Maven) Jun 24, 2026
Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs Moderate
CVE-2026-57285 was published for org.jenkins-ci.plugins:github-branch-source (Maven) Jun 24, 2026
Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names Moderate
CVE-2026-57286 was published for org.jenkins-ci.tools:git-parameter (Maven) Jun 24, 2026
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards Moderate
CVE-2026-69190 was published for org.graylog2:graylog2-server (Maven) Sep 22, 2026
kah-ja Credited to kah-ja
io.moquette:moquette-broker has a Missing Authorization issue High
CVE-2026-85058 was published for io.moquette:moquette-broker (Maven) Sep 18, 2026
Fireees Credited to Fireees and Robin-szu Robin-szu Robin-szu
Apache NiFi: Missing authorization when replacing Process Groups with restricted components High
CVE-2026-44914 was published for org.apache.nifi:nifi-web-api (Maven) Jun 22, 2026
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets Moderate
CVE-2026-55548 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
lucquach Credited to lucquach
de3erve Credited to de3erve
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce Moderate
CVE-2026-55545 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
cipher-creator Credited to cipher-creator
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities High
CVE-2026-55521 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
lucquach Credited to lucquach
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing High
CVE-2026-53966 was published for org.xwiki.platform:xwiki-platform-livedata-livetable (Maven) Aug 19, 2026
Jenkins exposes other users' timezone and view names to users with Overall/Read permission Moderate
CVE-2026-53439 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Jenkins: Missing permission check allows unauthorized cancellation of queue items Moderate
CVE-2026-53438 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center Moderate
CVE-2025-32781 was published for com.ctrip.framework.apollo:apollo (Maven) Jul 13, 2026
lesignals Credited to lesignals
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221) High
CVE-2026-54076 was published for com.arcadedb:arcadedb-engine (Maven) Jul 16, 2026
OpenRemote read-only asset users can write predicted datapoints Moderate
CVE-2026-49439 was published for io.openremote:openremote-manager (Maven) Jul 6, 2026
Hussien-Alzaghateet Credited to Hussien-Alzaghateet
GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field High
CVE-2026-46487 was published for org.geonetwork-opensource:geonetwork (Maven) Jul 1, 2026
jrdnull Credited to jrdnull and juanluisrp juanluisrp juanluisrp
ProTip! Advisories are also available from the GraphQL API