GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
351 advisories
Filter by severity
usememos/memos Cross-Site Request Forgery vulnerability
Moderate
CVE-2022-4850
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
usememos/memos Cross-Site Request Forgery vulnerability
Moderate
CVE-2022-4849
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
usememos/memos Cross-Site Request Forgery vulnerability
Moderate
CVE-2022-4845
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
Jenkins Sonar Gerrit Plugin vulnerable to Cross-Site Request Forgery
Moderate
CVE-2022-46688
was published
for
org.jenkins-ci.plugins:sonar-gerrit
(Maven)
Dec 12, 2022
kube-httpcache is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
GHSA-47xh-qxqv-mgvg
was published
for
github.com/mittwald/kube-httpcache
(Go)
Dec 2, 2022
Cross-Site Request Forgery in Moodle
Moderate
CVE-2022-45149
was published
for
moodle/moodle
(Composer)
Nov 23, 2022
Fastify: Incorrect Content-Type parsing can lead to CSRF attack
Moderate
CVE-2022-41919
was published
for
fastify
(npm)
Nov 21, 2022
Cross-Site Request Forgery in Jenkins Delete log Plugin
Moderate
CVE-2022-45393
was published
for
org.jenkins-ci.plugins:delete-log-plugin
(Maven)
Nov 16, 2022
Cross-Site Request Forgery in Jenkins Cluster Statistics Plugin
Moderate
CVE-2022-45398
was published
for
org.zeroturnaround:cluster-stats
(Maven)
Nov 16, 2022
Cross-Site Request Forgery in feehi/feehicms
Moderate
CVE-2022-4014
was published
for
feehi/feehicms
(Composer)
Nov 16, 2022
NodeBB vulnerable to Cross-Site Request Forgery
Moderate
CVE-2022-3978
was published
for
nodebb
(npm)
Nov 13, 2022
ProcessWire vulnerable to Cross-Site Request Forgery
Moderate
CVE-2022-40488
was published
for
processwire/processwire
(Composer)
Oct 31, 2022
CSRF vulnerability in Jenkins Katalon Plugin allows capturing credentials
Moderate
CVE-2022-43418
was published
for
org.jenkins-ci.plugins:katalon
(Maven)
Oct 19, 2022
The graphql-upload library included in Apollo Server 2 is vulnerable to CSRF mutations
Moderate
GHSA-2p3c-p3qw-69r4
was published
for
apollo-server
(npm)
Oct 12, 2022
AdGuardHome vulnerable to Cross-Site Request Forgery
Moderate
CVE-2022-32175
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Oct 11, 2022
rdiffweb Cross-Site Request Forgery vulnerability
Moderate
CVE-2022-3267
was published
for
rdiffweb
(pip)
Sep 23, 2022
CSRF vulnerability in Jenkins Security Inspector plugin
Moderate
CVE-2022-41236
was published
for
org.jenkins-ci.plugins:security-inspector
(Maven)
Sep 22, 2022
Jenkins NS-ND Integration Performance Publisher Plugin vulnerable to Cross-Site Request Forgery
Moderate
CVE-2022-41227
was published
for
io.jenkins.plugins:cavisson-ns-nd-integration
(Maven)
Sep 22, 2022
CSRF vulnerability in Jenkins Worksoft Execution Manager Plugin allows capturing credentials
Moderate
CVE-2022-41245
was published
for
org.jenkins-ci.plugins:ws-execution-manager
(Maven)
Sep 22, 2022
Jenkins SCM HttpClient Plugin vulnerable to Cross-Site Request Forgery
Moderate
CVE-2022-41249
was published
for
com.meowlomo.jenkins:scm-httpclient
(Maven)
Sep 22, 2022
CSRF vulnerability in Jenkins CONS3RT Plugin allow capturing credentials
Moderate
CVE-2022-41253
was published
for
org.jenkins-ci.plugins:cons3rt
(Maven)
Sep 22, 2022
rdiffweb CSRF could lead to disabling notifications in user profile
Moderate
CVE-2022-3233
was published
for
rdiffweb
(pip)
Sep 22, 2022
rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users
Moderate
CVE-2022-3232
was published
for
rdiffweb
(pip)
Sep 18, 2022
XWiki Cross-Site Request Forgery (CSRF) for actions on tags
Moderate
CVE-2022-36095
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Sep 16, 2022
Froxlor vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2022-3017
was published
for
froxlor/froxlor
(Composer)
Aug 29, 2022
ProTip!
Advisories are also available from the
GraphQL API