GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
6,194 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in Arif Nezami Better Author Bio allows Cross...
High
Unreviewed
CVE-2024-49229
was published
Oct 17, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Ahmet Imamoglu Ahmeti Wp Timeline allows...
High
Unreviewed
CVE-2024-49237
was published
Oct 17, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner...
High
Unreviewed
CVE-2024-49220
was published
Oct 17, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Julian Weinert // cs&m cSlider allows Stored...
High
Unreviewed
CVE-2024-49221
was published
Oct 17, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Shibu Lijack a.K.A CyberJack CJ Change Howdy...
High
Unreviewed
CVE-2024-49223
was published
Oct 17, 2024
Cross-Site Request Forgery (CSRF) vulnerability in WSIFY – Sales can fly Wsify Widget allows...
High
Unreviewed
CVE-2024-48048
was published
Oct 17, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Sumit Surai Featured Posts with Multiple...
Moderate
Unreviewed
CVE-2024-48031
was published
Oct 17, 2024
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget allows Cross...
Moderate
Unreviewed
CVE-2024-48037
was published
Oct 17, 2024
Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH...
Moderate
Unreviewed
CVE-2024-23785
was published
Oct 17, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Razon Komar Pal Linked Variation for...
Moderate
Unreviewed
CVE-2024-48047
was published
Oct 17, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Hans Matzen wp-Monalisa allows Cross Site...
Moderate
Unreviewed
CVE-2024-48038
was published
Oct 17, 2024
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-9352
was published
Oct 17, 2024
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-9351
was published
Oct 17, 2024
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro...
Moderate
Unreviewed
CVE-2024-48758
was published
Oct 16, 2024
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone...
High
Unreviewed
CVE-2024-20421
was published
Oct 16, 2024
Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF...
High
Unreviewed
CVE-2024-45693
was published
Oct 16, 2024
The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
High
Unreviewed
CVE-2024-8507
was published
Oct 16, 2024
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion...
High
Unreviewed
CVE-2020-36836
was published
Oct 16, 2024
The WP Lead Plus X plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions...
High
Unreviewed
CVE-2020-36839
was published
Oct 16, 2024
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-9649
was published
Oct 16, 2024
IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an...
Moderate
Unreviewed
CVE-2024-49340
was published
Oct 16, 2024
A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change...
High
Unreviewed
CVE-2024-41344
was published
Oct 15, 2024
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
Moderate
CVE-2024-48913
was published
for
hono
(npm)
Oct 15, 2024
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site...
Moderate
Unreviewed
CVE-2024-48278
was published
Oct 15, 2024
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions...
Moderate
Unreviewed
CVE-2024-45737
was published
Oct 14, 2024
ProTip!
Advisories are also available from the
GraphQL API