GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,471
Erlang
33
GitHub Actions
24
Go
2,180
Maven
5,000+
npm
3,836
NuGet
696
pip
3,555
Pub
12
RubyGems
910
Rust
908
Swift
38
Unreviewed advisories
All unreviewed
5,000+
725 advisories
Filter by severity
LocalAI Cross-site Scripting vulnerability
Low
CVE-2024-48057
was published
for
github.com/mudler/LocalAI
(Go)
Nov 5, 2024
Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack
High
CVE-2015-7537
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack
High
CVE-2015-7538
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack
Low
CVE-2015-5318
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Jenkins cross-site request forgery (CSRF) vulnerability
Moderate
CVE-2025-27624
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 6, 2025
Magento Open Source allows Cross-Site Request Forgery (CSRF)
Moderate
CVE-2024-20718
was published
for
magento/community-edition
(Composer)
Feb 15, 2024
Magento Open Source allows Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-39864
was published
for
magento/community-edition
(Composer)
May 24, 2022
Jenkins Convert To Pipeline Plugin vulnerable to cross-site request forgery
High
CVE-2023-28676
was published
for
org.jenkins-ci.plugins:convert-to-pipeline
(Maven)
Apr 2, 2023
Leantime allows Cross-Site Request Forgery (CSRF)
Moderate
GHSA-92xh-6x7v-4rmq
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
High
CVE-2024-34069
was published
for
Werkzeug
(pip)
May 6, 2024
Cross-Site Request Forgery in Apache Wicket
Moderate
CVE-2024-27439
was published
for
org.apache.wicket:wicket
(Maven)
Mar 19, 2024
Magento cross-site request forgery (CSRF) vulnerability via the GraphQL API
Moderate
CVE-2021-21027
was published
for
magento/community-edition
(Composer)
May 24, 2022
Cross-Site Request Forgery in moodle
High
CVE-2024-25982
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
CSRF vulnerability in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24402
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL
High
CVE-2025-24398
was published
for
io.jenkins.plugins:atlassian-bitbucket-server-integration
(Maven)
Jan 22, 2025
Cross-Site Request Forgery in CodeChecker API
High
CVE-2024-53829
was published
for
codechecker
(pip)
Jan 21, 2025
Cross-Site Request Forgery (CSRF) in strawberry-graphql
Moderate
CVE-2024-47082
was published
for
strawberry-graphql
(pip)
Sep 25, 2024
TYPO3 DB Check Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55945
was published
for
typo3/cms-lowlevel
(Composer)
Jan 14, 2025
TYPO3 Scheduler Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55924
was published
for
typo3/cms-scheduler
(Composer)
Jan 14, 2025
TYPO3 Indexed Search Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55923
was published
for
typo3/cms-indexed-search
(Composer)
Jan 14, 2025
TYPO3 Form Framework Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55922
was published
for
typo3/cms-form
(Composer)
Jan 14, 2025
TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55921
was published
for
typo3/cms-extensionmanager
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Dashboard Module
Moderate
CVE-2024-55920
was published
for
typo3/cms-dashboard
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Backend User Module
Moderate
CVE-2024-55894
was published
for
typo3/cms-beuser
(Composer)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API