GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
6,205 advisories
Filter by severity
The Featured Posts Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2024-10922
was published
Nov 7, 2024
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform...
High
Unreviewed
CVE-2024-51381
was published
Nov 5, 2024
Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the...
High
Unreviewed
CVE-2024-51382
was published
Nov 5, 2024
The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
High
Unreviewed
CVE-2024-10711
was published
Nov 5, 2024
The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting...
Moderate
Unreviewed
CVE-2024-9689
was published
Nov 5, 2024
LocalAI Cross-site Scripting vulnerability
Low
CVE-2024-48057
was published
for
github.com/mudler/LocalAI
(Go)
Nov 5, 2024
A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php,"...
Moderate
Unreviewed
CVE-2024-30617
was published
Nov 4, 2024
IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an...
Moderate
Unreviewed
CVE-2024-41744
was published
Nov 1, 2024
Broken Access Control vulnerability in Nickolas Bossinas WordPress File Upload allows Exploiting...
Moderate
Unreviewed
CVE-2024-39639
was published
Nov 1, 2024
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been...
Moderate
Unreviewed
CVE-2024-10605
was published
Nov 1, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Lukas Huser EKC Tournament Manager allows...
Critical
Unreviewed
CVE-2024-49674
was published
Oct 31, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets...
Moderate
Unreviewed
CVE-2024-49685
was published
Oct 31, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code...
Critical
Unreviewed
CVE-2024-43984
was published
Oct 31, 2024
Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue...
Moderate
Unreviewed
CVE-2024-43933
was published
Oct 31, 2024
Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request...
Moderate
Unreviewed
CVE-2024-43930
was published
Oct 31, 2024
The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery...
Moderate
Unreviewed
CVE-2024-9434
was published
Oct 31, 2024
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album...
High
Unreviewed
CVE-2024-48311
was published
Oct 31, 2024
A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified...
Moderate
Unreviewed
CVE-2024-10557
was published
Oct 31, 2024
A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of...
High
Unreviewed
CVE-2024-24777
was published
Oct 30, 2024
Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode...
Moderate
Unreviewed
CVE-2024-50466
was published
Oct 29, 2024
The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,...
High
Unreviewed
CVE-2024-9990
was published
Oct 29, 2024
A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the...
Moderate
Unreviewed
CVE-2024-6673
was published
Oct 29, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Gifford Cheung, Brian Watanabe, Chongsun Ahn...
High
Unreviewed
CVE-2024-49672
was published
Oct 29, 2024
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
Moderate
CVE-2024-46872
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Oct 29, 2024
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank...
Moderate
Unreviewed
CVE-2024-10448
was published
Oct 28, 2024
ProTip!
Advisories are also available from the
GraphQL API