GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,367
Maven
5,000+
npm
3,986
NuGet
720
pip
3,778
Pub
12
RubyGems
926
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
756 advisories
Filter by severity
Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs
High
CVE-2021-33338
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
ThinkCMF Cross Site Request Forgerly (CSRF) vulnerability
Moderate
CVE-2020-18151
was published
for
thinkcmf/thinkcmf
(Composer)
May 24, 2022
CSRF vulnerabilities in Jenkins requests-plugin Plugin
Moderate
CVE-2021-21675
was published
for
org.jenkins-ci.plugins:requests
(Maven)
May 24, 2022
Drupal Core Cross-Site Request Forgery (CSRF) vulnerability
High
CVE-2020-13663
was published
for
drupal/core
(Composer)
May 24, 2022
CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials
High
CVE-2021-21665
was published
for
com.xebialabs.deployit.ci:deployit-plugin
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Config File Provider Plugin allows deleting configuration files
Moderate
CVE-2021-21644
was published
for
org.jenkins-ci.plugins:config-file-provider
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Micro Focus Application Automation Tools Plugin
Moderate
CVE-2021-22512
was published
for
org.jenkins-ci.plugins:hp-application-automation-tools-plugin
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins promoted builds Plugin
Moderate
CVE-2021-21641
was published
for
org.jenkins-ci.plugins:promoted-builds
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Team Foundation Server Plugin allow capturing credentials
High
CVE-2021-21638
was published
for
org.jenkins-ci.plugins:tfs
(Maven)
May 24, 2022
CSRF vulnerability and in Jenkins OWASP Dependency-Track Plugin allow capturing credentials
High
CVE-2021-21633
was published
for
org.jenkins-ci.plugins:dependency-track
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Build With Parameters Plugin
High
CVE-2021-21629
was published
for
org.jenkins-ci.plugins:build-with-parameters
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Libvirt Agents Plugin
High
CVE-2021-21627
was published
for
org.jenkins-ci.plugins:libvirt-slave
(Maven)
May 24, 2022
Grav CMS Cross-Site Request Forgery (CSRF)
High
CVE-2020-29553
was published
for
getgrav/grav
(Composer)
May 24, 2022
CSRF vulnerability in Jenkins Configuration Slicing Plugin
High
CVE-2021-21617
was published
for
org.jenkins-ci.plugins:configurationslicing
(Maven)
May 24, 2022
Magento cross-site request forgery (CSRF) vulnerability via the GraphQL API
Moderate
CVE-2021-21027
was published
for
magento/community-edition
(Composer)
May 24, 2022
CakePHP allows method override parameters to bypass CSRF checks
High
CVE-2020-35239
was published
for
cakephp/cakephp
(Composer)
May 24, 2022
Cross-Site Request Forgery in JupyterHub
Moderate
CVE-2020-36191
was published
for
jupyterhub
(pip)
May 24, 2022
OpenCart Cross-Site Request Forgery (CSRF)
Low
CVE-2020-28838
was published
for
opencart/opencart
(Composer)
May 24, 2022
CSRF vulnerability in Jenkins Shelve Project Plugin
High
CVE-2020-2321
was published
for
org.jenkins-ci.plugins:shelve-project-plugin
(Maven)
May 24, 2022
Subrion CMS CSRF Vulnerability
High
CVE-2019-7357
was published
for
intelliants/subrion
(Composer)
May 24, 2022
CSRF vulnerability in Jenkins Active Directory Plugin
Moderate
CVE-2020-2303
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Maven Cascade Release Plugin
Moderate
CVE-2020-2295
was published
for
com.barchart.jenkins:maven-release-cascade
(Maven)
May 24, 2022
PyroCMS Vulnerable to CSRF
Moderate
CVE-2020-25262
was published
for
pyrocms/pyrocms
(Composer)
May 24, 2022
PyroCMS Vulnerable to CSRF
High
CVE-2020-25263
was published
for
pyrocms/pyrocms
(Composer)
May 24, 2022
CSRF vulnerability in Jenkins Shared Objects Plugin
Moderate
CVE-2020-2296
was published
for
org.jenkins-ci.plugins:shared-objects
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API