GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,339
Erlang
31
GitHub Actions
22
Go
2,099
Maven
5,000+
npm
3,763
NuGet
678
pip
3,448
Pub
12
RubyGems
892
Rust
883
Swift
37
Unreviewed advisories
All unreviewed
5,000+
319 advisories
Filter by severity
Cross-Site Request Forgery in moodle
High
CVE-2024-25982
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL
High
CVE-2025-24398
was published
for
io.jenkins.plugins:atlassian-bitbucket-server-integration
(Maven)
Jan 22, 2025
Cross-Site Request Forgery in CodeChecker API
High
CVE-2024-53829
was published
for
codechecker
(pip)
Jan 21, 2025
TYPO3 Scheduler Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55924
was published
for
typo3/cms-scheduler
(Composer)
Jan 14, 2025
TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55921
was published
for
typo3/cms-extensionmanager
(Composer)
Jan 14, 2025
pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints
High
CVE-2024-39163
was published
for
pyspider
(pip)
Dec 4, 2024
Avenwu Whistle Cross-Site Request Forgery (CSRF)
High
CVE-2024-55500
was published
for
whistle
(npm)
Dec 10, 2024
OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
High
CVE-2024-47879
was published
for
org.openrefine:main
(Maven)
Oct 24, 2024
Plone Cross-site request forgery (CSRF)
High
CVE-2008-0164
was published
for
Plone
(pip)
May 1, 2022
Selenium Server (Grid) CSRF
High
CVE-2022-28108
was published
for
org.seleniumhq.selenium:selenium-grid
(Maven)
Apr 20, 2022
Cross-Site Request Forgery in Webargs
High
CVE-2020-7965
was published
for
webargs
(pip)
Apr 7, 2021
Edgewall Trac Cross-site request forgery (CSRF) vulnerability
High
CVE-2006-5878
was published
for
trac
(pip)
May 1, 2022
Moodle has CSRF risk in Feedback non-respondents report
High
CVE-2024-43434
was published
for
moodle/moodle
(Composer)
Nov 7, 2024
rdiffweb vulnerable to Cross-Site Request Forgery
High
CVE-2022-4646
was published
for
rdiffweb
(pip)
Dec 22, 2022
rdiffweb CSRF vulnerability in profile's SSH keys can lead to unauthorized access
High
CVE-2022-3221
was published
for
rdiffweb
(pip)
Sep 16, 2022
rdiffweb Cross-Site Request Forgery vulnerability can lead to user email ID being changed
High
CVE-2022-3274
was published
for
rdiffweb
(pip)
Sep 23, 2022
python-engineio vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2019-13611
was published
for
python-engineio
(pip)
Jul 30, 2019
Cross-Site Request Forgery in sqlite-web
High
CVE-2021-23404
was published
for
sqlite-web
(pip)
Sep 9, 2021
Plone vulnerable to cross-site request forgery
High
CVE-2015-7293
was published
for
Plone
(pip)
May 17, 2022
CSRF vulnerability and missing permission check in Jenkins JiraTestResultReporter Plugin
High
CVE-2022-28136
was published
for
org.jenkins-ci.plugins:JiraTestResultReporter
(Maven)
Mar 30, 2022
Cross-Site Request Forgery (CSRF) in Luigi
High
CVE-2018-1000843
was published
for
luigi
(pip)
Dec 20, 2018
Kotti CSRF in the local roles implementation
High
CVE-2018-9856
was published
for
Kotti
(pip)
Jul 12, 2018
Kallithea cross-site request forgery (CSRF) vulnerability
High
CVE-2015-0276
was published
for
Kallithea
(pip)
May 13, 2022
IPython vulnerable to cross site request forgery (CSRF)
High
CVE-2015-5607
was published
for
ipython
(pip)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API