GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
55 advisories
Filter by severity
CSRF Vuln can expose user's QRcode
Low
GHSA-fxq4-r6mr-9x64
was published
for
Flask-Security-Too
(pip)
Apr 8, 2021
Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
High
CVE-2022-43719
was published
for
apache-superset
(pip)
Jan 16, 2023
Cross Site Request Forgery in mailman
High
CVE-2021-44227
was published
for
mailman
(pip)
Dec 16, 2021
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4164
was published
for
calibreweb
(pip)
Jan 21, 2022
Mirumee Saleor CSRF Protection Disabled
High
CVE-2019-13594
was published
for
saleor
(pip)
May 24, 2022
Web2py Cross-Site Request Forgery vulnerability
Moderate
CVE-2016-4808
was published
for
web2py
(pip)
May 17, 2022
wger Workout Manager Cross-Site Request Forgery vulnerability
High
CVE-2023-38759
was published
for
wger
(pip)
Aug 8, 2023
Cobbler Web Interface Lacks CSRF Protection
High
CVE-2011-4952
was published
for
cobbler
(pip)
Apr 22, 2022
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
High
CVE-2024-28233
was published
for
jupyterhub
(pip)
Mar 28, 2024
Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
High
CVE-2024-2196
was published
for
aim
(pip)
Apr 10, 2024
ESPHome vulnerable to Authentication bypass via Cross site request forgery
High
CVE-2024-29019
was published
for
esphome
(pip)
Mar 21, 2024
Cross-Site Request Forgery vulnerability in Prefect
High
CVE-2023-6022
was published
for
prefect
(pip)
Nov 16, 2023
Duplicate Advisory: Cross-Site Request Forgery in Gradio
Moderate
GHSA-3x9g-xfj5-fq84
was published
for
gradio
(pip)
Mar 21, 2024
•
withdrawn
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Moderate
CVE-2024-1727
was published
for
gradio
(pip)
May 21, 2024
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
High
CVE-2024-34069
was published
for
Werkzeug
(pip)
May 6, 2024
Cross-Site Request Forgery (CSRF) in Apache Airflow
High
CVE-2017-17835
was published
for
apache-airflow
(pip)
Jan 25, 2019
Apache Airflow vulnerable to CSRF Attacks
High
CVE-2019-0229
was published
for
apache-airflow
(pip)
Apr 18, 2019
archivy is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-4162
was published
for
archivy
(pip)
Jan 6, 2022
Cross-Site Request Forgery in MicroPyramid Django CRM
High
CVE-2019-11457
was published
for
django-crm
(pip)
Sep 11, 2019
Django Cross-Site Request Forgery vulnerability
High
CVE-2011-4140
was published
for
Django
(pip)
Jul 23, 2018
Django cross-site request forgery (CSRF) vulnerability
High
CVE-2008-3909
was published
for
django
(pip)
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API