GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,354 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll allows Stored...
High
Unreviewed
CVE-2024-51647
was published
Nov 9, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Lars Schenk Responsive Flickr Gallery allows...
High
Unreviewed
CVE-2024-51630
was published
Nov 9, 2024
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't...
High
Unreviewed
CVE-2019-20460
was published
Nov 7, 2024
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection.
High
Unreviewed
CVE-2020-11919
was published
Nov 7, 2024
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform...
High
Unreviewed
CVE-2024-51381
was published
Nov 5, 2024
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the...
High
Unreviewed
CVE-2024-51382
was published
Nov 5, 2024
The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
High
Unreviewed
CVE-2024-10711
was published
Nov 5, 2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component ...
High
Unreviewed
CVE-2024-35552
was published
May 22, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site...
High
Unreviewed
CVE-2024-43684
was published
Oct 4, 2024
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album...
High
Unreviewed
CVE-2024-48311
was published
Oct 31, 2024
A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of...
High
Unreviewed
CVE-2024-24777
was published
Oct 30, 2024
The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,...
High
Unreviewed
CVE-2024-9990
was published
Oct 29, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Gifford Cheung, Brian Watanabe, Chongsun Ahn...
High
Unreviewed
CVE-2024-49672
was published
Oct 29, 2024
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site...
High
Unreviewed
CVE-2024-9598
was published
Oct 25, 2024
A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack...
High
Unreviewed
CVE-2024-6959
was published
Oct 13, 2024
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3...
High
Unreviewed
CVE-2024-26271
was published
Oct 22, 2024
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4...
High
Unreviewed
CVE-2024-26273
was published
Oct 22, 2024
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3...
High
Unreviewed
CVE-2024-26272
was published
Oct 22, 2024
A bug in popup notifications delay calculation could have made it possible for an attacker to...
High
Unreviewed
CVE-2023-4047
was published
Aug 1, 2023
The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF...
High
Unreviewed
CVE-2023-52431
was published
Feb 13, 2024
OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection...
High
Unreviewed
CVE-2023-38885
was published
Nov 20, 2023
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by...
High
Unreviewed
CVE-2018-12364
was published
May 14, 2022
Cross-Site Request Forgery (CSRF) vulnerability in Henrique Rodrigues SafetyForms allows Blind...
High
Unreviewed
CVE-2024-49615
was published
Oct 20, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Back Link Tracker allows Blind...
High
Unreviewed
CVE-2024-49617
was published
Oct 20, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation allows...
High
Unreviewed
CVE-2024-49629
was published
Oct 20, 2024
ProTip!
Advisories are also available from the
GraphQL API