spotbugs
Security Risk Profile
0
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 2 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 3, 2025 to present
2
Total CVEs
0
Critical+High
1
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
0
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
0/100
low
⚠️ 1 Active Exploits
Severity Distribution
Critical
0High
0Medium
0Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
No CWE data available
Most Affected Products
1. tj-actions changed-files3
2. SpotBugs SpotBugs3
3. reviewdog Reviewdog3
4. SpotBugs spotbugs/sonar-findbugs1
5. reviewdog reviewdog/action-setup1
Recent Vulnerabilities
See more →https://www.theregister.com/2025/04/07/github_supply_chain_attack/
unknown
That massive GitHub supply chain attack? It all started with a stolen SpotBugs token
4/7/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/recent-github-supply-chain-attack-traced-to-leaked-spotbugs-token/
unknown
Recent GitHub supply chain attack traced to leaked SpotBugs token
4/3/2025⚠ Exploited🔧 No Patch
Monitor spotbugs in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.