GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
359 advisories
Filter by severity
CSRF vulnerability in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24402
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
Cross-Site Request Forgery (CSRF) in strawberry-graphql
Moderate
CVE-2024-47082
was published
for
strawberry-graphql
(pip)
Sep 25, 2024
TYPO3 DB Check Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55945
was published
for
typo3/cms-lowlevel
(Composer)
Jan 14, 2025
TYPO3 Indexed Search Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55923
was published
for
typo3/cms-indexed-search
(Composer)
Jan 14, 2025
TYPO3 Form Framework Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55922
was published
for
typo3/cms-form
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Dashboard Module
Moderate
CVE-2024-55920
was published
for
typo3/cms-dashboard
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Backend User Module
Moderate
CVE-2024-55894
was published
for
typo3/cms-beuser
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Log Module
Moderate
CVE-2024-55893
was published
for
typo3/cms-belog
(Composer)
Jan 14, 2025
Atro CSRF Middleware Bypass (security.checkOrigin)
Moderate
CVE-2024-56140
was published
for
astro
(npm)
Dec 18, 2024
Concrete CMS Cross Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2023-48651
was published
for
concrete5/concrete5
(Composer)
Feb 29, 2024
Concrete CMS Cross Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2023-48653
was published
for
concrete5/concrete5
(Composer)
Feb 29, 2024
Content Censorship in the InterPlanetary File System (IPFS) via Kademlia DHT abuse
Moderate
CVE-2023-26248
was published
for
github.com/libp2p/go-libp2p-kad-dht
(Go)
Oct 25, 2024
Cross-Site Request Forgery in Apache Wicket
Moderate
CVE-2024-27439
was published
for
org.apache.wicket:wicket
(Maven)
Mar 19, 2024
Cross-Site Request Forgery in modoboa
Moderate
CVE-2023-0438
was published
for
modoboa
(pip)
Jan 23, 2023
Cross-Site Request Forgery in modoboa
Moderate
CVE-2023-0406
was published
for
modoboa
(pip)
Jan 19, 2023
Modoboa is vulnerable to Cross-Site Request Forgery
Moderate
CVE-2023-0398
was published
for
modoboa
(pip)
Jan 19, 2023
Apache Airflow Cross-Site Request Forgery vulnerability
Moderate
CVE-2023-49920
was published
for
apache-airflow
(pip)
Dec 21, 2023
CSRF leading to delete account in wallabag/wallabag
Moderate
CVE-2023-0737
was published
for
wallabag/wallabag
(Composer)
Nov 15, 2024
Cross-Site Request Forgery in Anchor CMS
Moderate
CVE-2024-29338
was published
for
anchorcms/anchor-cms
(Composer)
Mar 22, 2024
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
Moderate
CVE-2024-48913
was published
for
hono
(npm)
Oct 15, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
Moderate
CVE-2024-46872
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Oct 29, 2024
Jenkins docker-build-step Plugin Cross-Site Request Forgery vulnerability
Moderate
CVE-2024-2215
was published
for
org.jenkins-ci.plugins:docker-build-step
(Maven)
Mar 6, 2024
rdiffweb CSRF could lead to disabling notifications in user profile
Moderate
CVE-2022-3233
was published
for
rdiffweb
(pip)
Sep 22, 2022
rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users
Moderate
CVE-2022-3232
was published
for
rdiffweb
(pip)
Sep 18, 2022
rdiffweb Cross-Site Request Forgery vulnerability
Moderate
CVE-2022-3267
was published
for
rdiffweb
(pip)
Sep 23, 2022
ProTip!
Advisories are also available from the
GraphQL API