GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,427
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
314 advisories
Filter by severity
Cross-Site Request Forgery in Jenkins dbCharts Plugin
High
CVE-2022-25205
was published
for
org.jenkins-ci.plugins:dbCharts
(Maven)
Feb 16, 2022
CSRF vulnerability in Jenkins Chef Sinatra Plugin allow XXE
High
CVE-2022-25207
was published
for
org.jenkins-ci.plugins:sinatra-chef-builder
(Maven)
Feb 16, 2022
etcd Cross-site Request Forgery (CSRF)
High
CVE-2018-1098
was published
for
go.etcd.io/etcd/v3
(Go)
Feb 15, 2022
Cross-Site Request Forgery in Magnolia CMS
High
CVE-2021-46366
was published
for
info.magnolia:magnolia-core
(Maven)
Feb 12, 2022
Cross Site Request Forgery in concrete5/concrete5
High
CVE-2021-22954
was published
for
concrete5/concrete5
(Composer)
Feb 11, 2022
Cross-Site Request Forgery in xwiki-platform
High
CVE-2021-32732
was published
for
org.xwiki.platform:xwiki-platform-administration-ui
(Maven)
Feb 10, 2022
Cross Site Request Forgery in Gitea
High
CVE-2021-45326
was published
for
github.com/go-gitea/gitea
(Go)
Feb 9, 2022
Cross-Site Request Forgery in Filebrowser
High
CVE-2021-46398
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Feb 5, 2022
CSRF token missing in Symfony
High
CVE-2022-23601
was published
for
symfony/framework-bundle
(Composer)
Feb 1, 2022
Cross Site Request Forgery in Moodle
High
CVE-2022-0335
was published
for
moodle/moodle
(Composer)
Jan 28, 2022
Cross-Site Request Forgery in yetiforce
High
CVE-2022-0269
was published
for
yetiforce/yetiforce-crm
(Composer)
Jan 27, 2022
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4164
was published
for
calibreweb
(pip)
Jan 21, 2022
Cross-Site Request Forgery in Jenkins Bitbucket Branch Source Plugin
High
CVE-2022-20619
was published
for
org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source
(Maven)
Jan 13, 2022
Cross-Site Request Forgery in com.softwaremill.akka-http-session:core_2.12
High
CVE-2020-28452
was published
for
com.softwaremill.akka-http-session:core_2.12
(Maven)
Jan 6, 2022
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4131
was published
for
remdex/livehelperchat
(Composer)
Jan 5, 2022
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4130
was published
for
snipe/snipe-it
(Composer)
Jan 5, 2022
Cross-site Request Forgery (CSRF)
High
CVE-2017-1000069
was published
for
github.com/bitly/oauth2_proxy
(Go)
Dec 20, 2021
Cross Site Request Forgery in mailman
High
CVE-2021-44227
was published
for
mailman
(pip)
Dec 16, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4017
was published
for
showdoc/showdoc
(Composer)
Dec 3, 2021
Cross-Site Request Forgery in PiranhaCMS
High
CVE-2021-25976
was published
for
Piranha
(NuGet)
Nov 17, 2021
Cross Site Request Forgery in kindeditor
High
CVE-2021-42228
was published
for
kindeditor
(npm)
Oct 18, 2021
Cross-Site-Request-Forgery in Backend
High
CVE-2021-41113
was published
for
typo3/cms
(Composer)
Oct 5, 2021
Cross-Site Request Forgery in GilaCMS
High
CVE-2020-20693
was published
for
gilacms/gila
(Composer)
Sep 30, 2021
Cross-Site Request Forgery in sqlite-web
High
CVE-2021-23404
was published
for
sqlite-web
(pip)
Sep 9, 2021
Cross-Site Request Forgery (CSRF) can run untrusted code on Rundeck server
High
CVE-2021-39133
was published
for
org.rundeck:rundeck-core
(Maven)
Sep 1, 2021
ProTip!
Advisories are also available from the
GraphQL API