GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,340
Erlang
31
GitHub Actions
22
Go
2,101
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
885
Swift
37
Unreviewed advisories
All unreviewed
5,000+
6,709 advisories
Filter by severity
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing...
High
Unreviewed
CVE-2021-43353
was published
Jan 19, 2022
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5,...
High
Unreviewed
CVE-2022-0154
was published
Jan 19, 2022
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart...
High
Unreviewed
CVE-2022-0215
was published
Jan 19, 2022
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7...
High
Unreviewed
CVE-2022-0180
was published
Jan 18, 2022
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF...
Moderate
Unreviewed
CVE-2021-25025
was published
Jan 18, 2022
Cross-Site Request Forgery (CSRF) vulnerability discovered in PHP Everywhere (WordPress plugin)...
High
Unreviewed
CVE-2021-23227
was published
Jan 14, 2022
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the...
High
Unreviewed
CVE-2021-41597
was published
Jan 13, 2022
Cross-Site Request Forgery in Jenkins Mailer Plugin
Moderate
CVE-2022-20613
was published
for
org.jenkins-ci.plugins:mailer
(Maven)
Jan 13, 2022
Cross-Site Request Forgery in Jenkins Bitbucket Branch Source Plugin
High
CVE-2022-20619
was published
for
org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source
(Maven)
Jan 13, 2022
CSRF vulnerability in Jenkins batch task Plugin
Moderate
CVE-2022-23115
was published
for
org.jenkins-ci.plugins:batch-task
(Maven)
Jan 13, 2022
CSRF vulnerability and missing permission checks in Jenkins Publish Over SSH Plugin
Moderate
CVE-2022-23111
was published
for
org.jenkins-ci.plugins:publish-over-ssh
(Maven)
Jan 13, 2022
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3...
High
Unreviewed
CVE-2021-34086
was published
Jan 11, 2022
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37...
High
Unreviewed
CVE-2021-46147
was published
Jan 11, 2022
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to...
High
Unreviewed
CVE-2021-25051
was published
Jan 11, 2022
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows...
High
Unreviewed
CVE-2021-25052
was published
Jan 11, 2022
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to...
High
Unreviewed
CVE-2021-25053
was published
Jan 11, 2022
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro...
Critical
Unreviewed
CVE-2021-25032
was published
Jan 11, 2022
A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0...
Moderate
Unreviewed
CVE-2021-46080
was published
Jan 7, 2022
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-4168
was published
for
showdoc/showdoc
(Composer)
Jan 6, 2022
archivy is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-4162
was published
for
archivy
(pip)
Jan 6, 2022
Cross-Site Request Forgery in com.softwaremill.akka-http-session:core_2.12
High
CVE-2020-28452
was published
for
com.softwaremill.akka-http-session:core_2.12
(Maven)
Jan 6, 2022
Cross-Site Request Forgery in Moodle
Moderate
CVE-2020-1692
was published
for
moodle/moodle
(Composer)
Jan 6, 2022
CSRF forgery protection bypass in solidus_frontend
Moderate
CVE-2021-43846
was published
for
solidus_frontend
(RubyGems)
Jan 6, 2022
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4131
was published
for
remdex/livehelperchat
(Composer)
Jan 5, 2022
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4130
was published
for
snipe/snipe-it
(Composer)
Jan 5, 2022
ProTip!
Advisories are also available from the
GraphQL API