GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,790
Erlang
36
GitHub Actions
29
Go
2,370
Maven
5,000+
npm
3,994
NuGet
720
pip
3,783
Pub
12
RubyGems
927
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
55 advisories
Filter by severity
Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and...
Low
Unreviewed
CVE-2025-52463
was published
Jul 2, 2025
Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF...
Low
Unreviewed
CVE-2025-36576
was published
Jun 10, 2025
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin...
Low
Unreviewed
CVE-2024-57611
was published
Jan 16, 2025
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net...
Low
Unreviewed
CVE-2024-57159
was published
Jan 16, 2025
An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the...
Low
Unreviewed
CVE-2025-23113
was published
Jan 11, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request...
Low
Unreviewed
CVE-2024-13293
was published
Jan 9, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request...
Low
Unreviewed
CVE-2024-13261
was published
Jan 9, 2025
The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when...
Low
Unreviewed
CVE-2024-5030
was published
Nov 18, 2024
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System...
Low
Unreviewed
CVE-2024-42792
was published
Aug 26, 2024
An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary...
Low
Unreviewed
CVE-2024-40455
was published
Jul 16, 2024
Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2...
Low
Unreviewed
CVE-2024-36452
was published
Jul 10, 2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component ...
Low
Unreviewed
CVE-2024-39157
was published
Jun 27, 2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component ...
Low
Unreviewed
CVE-2024-39156
was published
Jun 27, 2024
A Cross-site request forgery (CSRF) flaw was found in Keycloak and occurs due to the lack of a...
Low
Unreviewed
CVE-2024-5203
was published
Jun 12, 2024
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal...
Low
Unreviewed
CVE-2024-35039
was published
May 16, 2024
The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating...
Low
Unreviewed
CVE-2024-3629
was published
May 15, 2024
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating...
Low
Unreviewed
CVE-2024-3823
was published
May 15, 2024
The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk...
Low
Unreviewed
CVE-2024-3471
was published
May 2, 2024
The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is...
Low
Unreviewed
CVE-2024-3076
was published
Apr 26, 2024
A potential security vulnerability has been identified in Hewlett Packard Enterprise...
Low
Unreviewed
CVE-2024-22438
was published
Apr 15, 2024
Cross-Site Request Forgery (CSRF) vulnerability in SumoMe Sumo.This issue affects Sumo: from n/a...
Low
Unreviewed
CVE-2024-31265
was published
Apr 12, 2024
The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Low
Unreviewed
CVE-2023-7048
was published
Jan 11, 2024
Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an...
Low
Unreviewed
CVE-2023-6251
was published
Nov 24, 2023
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
Low
Unreviewed
CVE-2023-5899
was published
Nov 1, 2023
ProTip!
Advisories are also available from the
GraphQL API