GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,901 advisories
Filter by severity
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through...
Moderate
Unreviewed
CVE-2023-45374
was published
Oct 9, 2023
A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations...
Moderate
Unreviewed
CVE-2024-5815
was published
Jul 17, 2024
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation...
Moderate
Unreviewed
CVE-2024-7864
was published
Sep 13, 2024
The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places,...
Moderate
Unreviewed
CVE-2024-6017
was published
Sep 12, 2024
The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting...
Moderate
Unreviewed
CVE-2024-3163
was published
Sep 12, 2024
The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating...
Moderate
Unreviewed
CVE-2024-7859
was published
Sep 12, 2024
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places,...
Moderate
Unreviewed
CVE-2024-7817
was published
Sep 12, 2024
The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in...
Moderate
Unreviewed
CVE-2024-7862
was published
Sep 12, 2024
The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its...
Moderate
Unreviewed
CVE-2024-7820
was published
Sep 12, 2024
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when...
Moderate
Unreviewed
CVE-2024-6856
was published
Sep 8, 2024
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit...
Moderate
Unreviewed
CVE-2024-6855
was published
Sep 8, 2024
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its...
Moderate
Unreviewed
CVE-2024-6925
was published
Sep 8, 2024
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when...
Moderate
Unreviewed
CVE-2024-6852
was published
Sep 8, 2024
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating...
Moderate
Unreviewed
CVE-2024-6853
was published
Sep 8, 2024
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,...
Moderate
Unreviewed
CVE-2023-2919
was published
Sep 10, 2024
A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e....
Moderate
Unreviewed
CVE-2024-2911
was published
Mar 27, 2024
The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could...
Moderate
Unreviewed
CVE-2024-7688
was published
Sep 9, 2024
The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and...
Moderate
Unreviewed
CVE-2023-6503
was published
Jan 29, 2024
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to...
Moderate
Unreviewed
CVE-2024-45172
was published
Sep 4, 2024
A vulnerability has been found in SourceCodester Insurance Management System 1.0 and classified...
Moderate
Unreviewed
CVE-2024-8414
was published
Sep 4, 2024
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery...
Moderate
Unreviewed
CVE-2024-45270
was published
Sep 2, 2024
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery...
Moderate
Unreviewed
CVE-2024-45269
was published
Sep 2, 2024
REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead...
Moderate
Unreviewed
CVE-2024-45527
was published
Sep 2, 2024
The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up...
Moderate
Unreviewed
CVE-2024-8319
was published
Aug 30, 2024
Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira...
Moderate
Unreviewed
CVE-2024-23737
was published
Jul 2, 2024
ProTip!
Advisories are also available from the
GraphQL API