GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,339
Erlang
31
GitHub Actions
22
Go
2,098
Maven
5,000+
npm
3,762
NuGet
678
pip
3,448
Pub
12
RubyGems
892
Rust
883
Swift
37
Unreviewed advisories
All unreviewed
5,000+
6,704 advisories
Filter by severity
A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary...
Moderate
Unreviewed
CVE-2022-26588
was published
Apr 9, 2022
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800...
High
Unreviewed
CVE-2022-20774
was published
Apr 7, 2022
The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating...
Moderate
Unreviewed
CVE-2022-0830
was published
Apr 5, 2022
Cross-Site Request Forgery in YOURLS
Low
CVE-2022-0088
was published
for
yourls/yourls
(Composer)
Apr 4, 2022
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password...
High
Unreviewed
CVE-2022-27432
was published
Mar 31, 2022
An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators...
High
Unreviewed
CVE-2021-44312
was published
Mar 31, 2022
CSRF vulnerability and missing permission check in Jenkins JiraTestResultReporter Plugin
High
CVE-2022-28136
was published
for
org.jenkins-ci.plugins:JiraTestResultReporter
(Maven)
Mar 30, 2022
CSRF vulnerability in Jenkins RocketChat Notifier Plugin
Moderate
CVE-2022-28138
was published
for
org.jenkins-ci.plugins:rocketchatnotifier
(Maven)
Mar 30, 2022
CSRF vulnerability in Proxmox Plugin
Moderate
CVE-2022-28143
was published
for
org.jenkins-ci.plugins:proxmox
(Maven)
Mar 30, 2022
CSRF vulnerability in Jenkins Job and Node ownership Plugin
Moderate
CVE-2022-28152
was published
for
com.synopsys.jenkinsci:ownership
(Maven)
Mar 30, 2022
Cross site request forgery in Jenkins Job and Node ownership Plugin
High
CVE-2022-28150
was published
for
com.synopsys.jenkinsci:ownership
(Maven)
Mar 30, 2022
The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related...
Moderate
Unreviewed
CVE-2021-24978
was published
Mar 29, 2022
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when...
High
Unreviewed
CVE-2022-0499
was published
Mar 29, 2022
The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of...
Moderate
Unreviewed
CVE-2022-0833
was published
Mar 29, 2022
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in...
High
Unreviewed
CVE-2022-0770
was published
Mar 29, 2022
Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE...
High
Unreviewed
CVE-2022-0427
was published
Mar 29, 2022
Cross-Site Request Forgery in Anchor CMS
Moderate
CVE-2022-25576
was published
for
anchorcms/anchor-cms
(Composer)
Mar 26, 2022
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is...
High
Unreviewed
CVE-2022-25523
was published
Mar 26, 2022
Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history...
High
Unreviewed
CVE-2022-25268
was published
Mar 25, 2022
An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that...
High
Unreviewed
CVE-2021-43738
was published
Mar 24, 2022
An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can...
Moderate
Unreviewed
CVE-2021-43737
was published
Mar 24, 2022
Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin)...
Moderate
Unreviewed
CVE-2022-25608
was published
Mar 24, 2022
A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers...
High
Unreviewed
CVE-2022-24235
was published
Mar 22, 2022
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF...
High
Unreviewed
CVE-2021-24905
was published
Mar 22, 2022
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper...
High
Unreviewed
CVE-2022-0229
was published
Mar 22, 2022
ProTip!
Advisories are also available from the
GraphQL API