Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

113 advisories

Loading
Apache Struts vulnerable to possible DoS attack when using URLValidator Moderate
CVE-2016-4465 was published for org.apache.struts:struts2-core (Maven) May 17, 2022
sunSUNQ Credited to sunSUNQ
Improper Input Validation in OpenSymphony XWork Moderate
CVE-2008-6504 was published for com.opensymphony:xwork (Maven) May 17, 2022
Apache Axis2 has Improper Input Validation Moderate
CVE-2012-5785 was published for org.apache.axis2:axis2 (Maven) May 17, 2022
steinybot Credited to steinybot
Improper Input Validation in Apache POI Moderate
CVE-2014-3574 was published for org.apache.poi:poi (Maven) May 17, 2022
MarkLee131 Credited to MarkLee131
Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users Moderate
CVE-2011-1475 was published for org.apache.tomcat:tomcat (Maven) May 17, 2022
Improper Input Validation in Apache Batik Moderate
CVE-2015-0250 was published for org.apache.xmlgraphics:batik (Maven) May 17, 2022
Denial of service in Apache Tomcat Moderate
CVE-2014-0095 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) May 17, 2022
q5438722 Credited to q5438722 and sunSUNQ sunSUNQ sunSUNQ
JBoss RichFaces Improper Input Validation vulnerability Moderate
CVE-2014-0086 was published for org.richfaces:richfaces (Maven) May 17, 2022
Jenkins has CRLF Injection Vulnerability in the CLI Moderate
CVE-2016-0789 was published for org.jenkins-ci.main:jenkins-core (Maven) May 14, 2022
Improper Input Validation in Apache Tomcat Moderate
CVE-2011-4858 was published for org.apache.tomcat:tomcat (Maven) May 14, 2022
MitM on Jenkins Maven Plugin Moderate
CVE-2017-1000397 was published for org.jenkins-ci.main:maven-plugin (Maven) May 14, 2022
q5438722 Credited to q5438722
Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks Moderate
CVE-2017-1000402 was published for org.jenkins-ci.plugins:swarm-client (Maven) May 14, 2022
Apache Struts vulnerable to possible DoS attack when using URLValidator Moderate
CVE-2016-8738 was published for org.apache.struts:struts2-core (Maven) May 14, 2022
sunSUNQ Credited to sunSUNQ
Arbitrary file write vulnerability in Jenkins Fortify CloudScan Plugin Moderate
CVE-2018-1000607 was published for org.jenkins-ci.plugins:fortify-cloudscan-jenkins-plugin (Maven) May 14, 2022
Improper Input Validation in Apache Jackrabbit Moderate
CVE-2015-1833 was published for org.apache.jackrabbit:jackrabbit-core (Maven) May 14, 2022
MarkLee131 Credited to MarkLee131
Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandler Moderate
CVE-2010-1587 was published for org.apache.activemq:activemq-web-console (Maven) May 14, 2022
sunSUNQ Credited to sunSUNQ
Improper Input Validation in Bouncy Castle Moderate
CVE-2013-1624 was published for org.bouncycastle:bcprov-jdk15on (Maven) May 14, 2022
Jenkins allows HTTP Injection and Response Splitting Moderate
CVE-2012-6072 was published for org.jenkins-ci.main:jenkins-core (Maven) May 14, 2022
Improper Input Validation in Apache Karaf Moderate
CVE-2014-0219 was published for org.apache.karaf:apache-karaf (Maven) May 14, 2022
Improper Input Validation in Jetty Moderate
CVE-2011-4461 was published for org.eclipse.jetty:jetty-server (Maven) May 14, 2022
Improper Input Validation in Apache Tomcat Moderate
CVE-2011-2526 was published for org.apache.tomcat:tomcat (Maven) May 14, 2022
sunSUNQ Credited to sunSUNQ
Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions Moderate
CVE-2012-3544 was published for org.apache.tomcat:tomcat (Maven) May 14, 2022
Apache Tomcat is vulnerable to HTTP request-smuggling Moderate
CVE-2013-4286 was published for org.apache.tomcat:tomcat (Maven) May 14, 2022
sunSUNQ Credited to sunSUNQ
Improper Input Validation in Apache Tomcat Moderate
CVE-2014-0033 was published for org.apache.tomcat:tomcat (Maven) May 14, 2022
Improper Input Validation in Apache Tomcat Moderate
CVE-2014-0227 was published for org.apache.tomcat:tomcat (Maven) May 14, 2022
MarkLee131 Credited to MarkLee131
ProTip! Advisories are also available from the GraphQL API