GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
2,704 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform...
High
Unreviewed
CVE-2024-51381
was published
Nov 5, 2024
The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
High
Unreviewed
CVE-2024-10711
was published
Nov 5, 2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component ...
High
Unreviewed
CVE-2024-35552
was published
May 22, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site...
High
Unreviewed
CVE-2024-43684
was published
Oct 4, 2024
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album...
High
Unreviewed
CVE-2024-48311
was published
Oct 31, 2024
A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of...
High
Unreviewed
CVE-2024-24777
was published
Oct 30, 2024
The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,...
High
Unreviewed
CVE-2024-9990
was published
Oct 29, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Gifford Cheung, Brian Watanabe, Chongsun Ahn...
High
Unreviewed
CVE-2024-49672
was published
Oct 29, 2024
rdiffweb vulnerable to Cross-Site Request Forgery
High
CVE-2022-4646
was published
for
rdiffweb
(pip)
Dec 22, 2022
rdiffweb CSRF vulnerability in profile's SSH keys can lead to unauthorized access
High
CVE-2022-3221
was published
for
rdiffweb
(pip)
Sep 16, 2022
rdiffweb Cross-Site Request Forgery vulnerability can lead to user email ID being changed
High
CVE-2022-3274
was published
for
rdiffweb
(pip)
Sep 23, 2022
python-engineio vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2019-13611
was published
for
python-engineio
(pip)
Jul 30, 2019
Cross-Site Request Forgery in sqlite-web
High
CVE-2021-23404
was published
for
sqlite-web
(pip)
Sep 9, 2021
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site...
High
Unreviewed
CVE-2024-9598
was published
Oct 25, 2024
OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
High
CVE-2024-47879
was published
for
org.openrefine:main
(Maven)
Oct 24, 2024
A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack...
High
Unreviewed
CVE-2024-6959
was published
Oct 13, 2024
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3...
High
Unreviewed
CVE-2024-26271
was published
Oct 22, 2024
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4...
High
Unreviewed
CVE-2024-26273
was published
Oct 22, 2024
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3...
High
Unreviewed
CVE-2024-26272
was published
Oct 22, 2024
A bug in popup notifications delay calculation could have made it possible for an attacker to...
High
Unreviewed
CVE-2023-4047
was published
Aug 1, 2023
The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF...
High
Unreviewed
CVE-2023-52431
was published
Feb 13, 2024
OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection...
High
Unreviewed
CVE-2023-38885
was published
Nov 20, 2023
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by...
High
Unreviewed
CVE-2018-12364
was published
May 14, 2022
Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation allows...
High
Unreviewed
CVE-2024-49629
was published
Oct 20, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Back Link Tracker allows Blind...
High
Unreviewed
CVE-2024-49617
was published
Oct 20, 2024
ProTip!
Advisories are also available from the
GraphQL API