GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,079
Erlang
29
GitHub Actions
19
Go
1,905
Maven
5,000+
npm
3,637
NuGet
638
pip
3,256
Pub
10
RubyGems
869
Rust
820
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
5,295 advisories
Filter by severity
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin...
Moderate
Unreviewed
CVE-2024-46485
was published
Sep 25, 2024
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an...
Critical
Unreviewed
CVE-2024-44677
was published
Sep 10, 2024
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross...
Moderate
Unreviewed
CVE-2024-7386
was published
Sep 25, 2024
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an...
High
Unreviewed
CVE-2024-20437
was published
Sep 25, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font allows Cross Site...
Moderate
Unreviewed
CVE-2024-47305
was published
Sep 25, 2024
Cross-Site Request Forgery (CSRF) vulnerability in GiveWP.This issue affects GiveWP: from n/a...
Moderate
Unreviewed
CVE-2024-47315
was published
Sep 25, 2024
The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2024-8476
was published
Sep 25, 2024
The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
High
Unreviewed
CVE-2024-8795
was published
Sep 24, 2024
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through...
Moderate
Unreviewed
CVE-2023-45374
was published
Oct 9, 2023
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
High
Unreviewed
CVE-2024-46394
was published
Sep 19, 2024
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via ...
High
Unreviewed
CVE-2024-46086
was published
Sep 18, 2024
Cross-Site Request Forgery (CSRF) vulnerability in LikeBtn Like Button Rating allows Cross-Site...
High
Unreviewed
CVE-2024-44064
was published
Sep 18, 2024
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via ...
High
Unreviewed
CVE-2024-46085
was published
Sep 17, 2024
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via ...
High
Unreviewed
CVE-2024-46362
was published
Sep 17, 2024
A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations...
Moderate
Unreviewed
CVE-2024-5815
was published
Jul 17, 2024
The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
High
Unreviewed
CVE-2024-8490
was published
Sep 17, 2024
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation...
Moderate
Unreviewed
CVE-2024-7864
was published
Sep 13, 2024
The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places,...
Moderate
Unreviewed
CVE-2024-6017
was published
Sep 12, 2024
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
High
Unreviewed
CVE-2024-7423
was published
Sep 13, 2024
The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting...
Moderate
Unreviewed
CVE-2024-3163
was published
Sep 12, 2024
The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating...
Moderate
Unreviewed
CVE-2024-7859
was published
Sep 12, 2024
The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in...
Moderate
Unreviewed
CVE-2024-7862
was published
Sep 12, 2024
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places,...
Moderate
Unreviewed
CVE-2024-7817
was published
Sep 12, 2024
The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its...
Moderate
Unreviewed
CVE-2024-7820
was published
Sep 12, 2024
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when...
Moderate
Unreviewed
CVE-2024-6856
was published
Sep 8, 2024
ProTip!
Advisories are also available from the
GraphQL API